Skip to main content

VLC Media Player "get_chunk_header()" Double-Free Vulnerability

Last Update Date: 22 Dec 2011 11:08 Release Date: 22 Dec 2011 5242 Views

RISK: High Risk

TYPE: Clients - Audio & Video

TYPE: Audio & Video

A vulnerability has been identified in VLC Media Player, which potentially can be exploited by malicious people to compromise a user's system.

The vulnerability is caused due to a double-free error within the "get_chunk_header()" function (modules/demux/ty.c) of the TiVo demuxer and can be exploited to corrupt memory by e.g. tricking a user into opening a specially crafted TiVo (*.ty) file.


Impact

  • Remote Code Execution

System / Technologies affected

  • VLC media player versions 0.9.0 through 1.1.12

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.

  • Update to version 1.1.13.

Vulnerability Identifier

  • No CVE information is available

Source


Related Link