VLC Media Player "get_chunk_header()" Double-Free Vulnerability
RISK: High Risk
TYPE: Clients - Audio & Video
A vulnerability has been identified in VLC Media Player, which potentially can be exploited by malicious people to compromise a user's system.
The vulnerability is caused due to a double-free error within the "get_chunk_header()" function (modules/demux/ty.c) of the TiVo demuxer and can be exploited to corrupt memory by e.g. tricking a user into opening a specially crafted TiVo (*.ty) file.
Impact
- Remote Code Execution
System / Technologies affected
- VLC media player versions 0.9.0 through 1.1.12
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- Update to version 1.1.13.
Vulnerability Identifier
- No CVE information is available
Source
Related Link
Share with