VLC Media Player Real Demuxer File Handling Array Indexing Vulnerability
RISK: Medium Risk
A vulnerability has been identified in VLC Media Player, which could be exploited by attackers to execute arbitrary code. This issue is caused by an array indexing error in the "Close()" and "DemuxAudioMethod1()" [modules/demux/real.c] functions within the Real demuxer when processing a Real Media file with a zero "i_subpackets" value, which could be exploited by attackers to crash an affected application or compromise a vulnerable system by convincing a user to open a malicious media file or to visit a specially crafted web page.
Impact
- Remote Code Execution
System / Technologies affected
- VLC Media Player version 1.1.5 and prior
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- Upgrade to VLC Media Player version 1.1.6 :
http://www.videolan.org/vlc/
Vulnerability Identifier
Source
Related Link
Share with