Skip to main content

VLC Media Player RealMedia and AVI File Parsing Vulnerabilities

Last Update Date: 14 Jul 2011 15:53 Release Date: 14 Jul 2011 6264 Views

RISK: High Risk

TYPE: Clients - Audio & Video

TYPE: Audio & Video

Two vulnerabilities have identified  in VLC Media Player, which can be exploited by malicious people to compromise a user's system.

  1. An integer overflow error when parsing a RealAudio data block within RealMedia (RM) files can be exploited to cause a heap-based buffer overflow.
  2. An integer underflow error when parsing the "strf" chunk within AVI files can be exploited to cause a heap-based buffer overflow.

Impact

  • Remote Code Execution

System / Technologies affected

  • VLC media player 1.x

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.

  • Fixed in the GIT repository.
  • Fixes will be available in version 1.1.11.

 


Vulnerability Identifier


Source


Related Link