Skip to main content

VLC Media Player ASF Movie Buffer Overflow Vulnerability

Last Update Date: 31 Jan 2013 19:17 Release Date: 31 Jan 2013 3666 Views

RISK: High Risk

TYPE: Clients - Audio & Video

TYPE: Audio & Video

A vulnerability has been identified in VLC Media Player. A remote user can cause arbitrary code to be executed on the target user's system.

 

A remote user can create a specially crafted ASF movie that, when loaded by the target user, will trigger a buffer overflow and execute arbitrary code on the target system. The code will run with the privileges of the target user.

 

Note: Vendor patch is currently unavailable. The fix will be included in upcoming version 2.0.6.


Impact

  • Remote Code Execution

System / Technologies affected

  • Version 2.0.5 and prior

Solutions

  • Note: Vendor patch is currently unavailable. The fix will be included in upcoming version 2.0.6.

Vulnerability Identifier

  • No CVE information is available

Source


Related Link