VideoLAN Security Bulletin VLC 3.0.11 VideoLAN
http://www.videolan.org/security/sb-vlc3011.html
>Details
>
>A remote user could create a specifically crafted file that could trigger a buffer overflow in VLC's H26X packetizer
>Impact
>
>If successful, a malicious third party could trigger either a crash of VLC or an arbitratry code execution with the privileges of the target user.
>
>While these issues in themselves are most likely to just crash the player, we can't exclude that they could be combined to leak user informations or remotely execute code. ASLR and DEP help reduce the likelyness of code execution, but may be bypassed.
>
>We have not seen exploits performing code execution through these vulnerability