VLC Player Buffer Overflow Vulnerability
Last Update Date:
10 Jul 2012
Release Date:
9 Jul 2012
5072
Views
RISK: High Risk
TYPE: Clients - Audio & Video
A vulnerability has been identified in VLC Player. which can be exploited by remote user to compromise a vulnerable system.
A remote user can create a specially crafted file that, when loaded by the target user, will trigger a heap overflow and execute arbitrary code on the target system. The code will run with the privileges of the target user.
The vulnerability resides in the Ogg_DecodePacket() function in 'modules/demux/ogg.c'.
Impact
- Remote Code Execution
System / Technologies affected
- VLC Player version 2.0.2 prior
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- Update to version 2.0.2.
Vulnerability Identifier
Source
Related Link
Share with