Skip to main content

VLC Media Player AMV and NSV Data Processing Vulnerability

Last Update Date: 25 Mar 2011 11:43 Release Date: 25 Mar 2011 6479 Views

RISK: High Risk

TYPE: Clients - Audio & Video

TYPE: Audio & Video

Two vulnerabilities have been identified in VLC, which could be exploited by remote attackers to compromise a vulnerable system.  Due to a memory corruption error in the "libdirectx" plugin when processing malformed NSV or AMV data, which could be exploited by remote attackers to execute arbitrary code by tricking a user into opening a malicious file or visiting a specially crafted web page.


Impact

  • Remote Code Execution

System / Technologies affected

  • VLC Media Player version 1.1.7 and prior

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.


Vulnerability Identifier


Source


Related Link