VLC Media Player AMV and NSV Data Processing Vulnerability
RISK: High Risk
TYPE: Clients - Audio & Video
Two vulnerabilities have been identified in VLC, which could be exploited by remote attackers to compromise a vulnerable system. Due to a memory corruption error in the "libdirectx" plugin when processing malformed NSV or AMV data, which could be exploited by remote attackers to execute arbitrary code by tricking a user into opening a malicious file or visiting a specially crafted web page.
Impact
- Remote Code Execution
System / Technologies affected
- VLC Media Player version 1.1.7 and prior
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- Upgrade to VLC Media Player version 1.1.8 :
http://www.videolan.org/vlc/
Vulnerability Identifier
Source
Related Link
Share with