Hole In Vlc Media Player


Recommended Posts

26 June 2009, 14:39

Hole in VLC Media Player

According to security service provider Secunia, a vulnerability in the Windows version of the VLC media player can be exploited in order to compromise a system. An attack would require the attacker to get the victim to open a play list file with an overly long smb:// URI. The cause of the problem is a buffer overflow in the Win32AddConnection function in modules/access/smb.c

The error was discovered in version 0.9.9 of VLC, but is likely to exist in other versions. The VLC developers have fixed the problem in their Git repository, but describe the problem only as a denial of service vulnerability which crashes the player. Officially, only version 0.9.9 is available as source code and binary for Windows.

See also:

Fix a segfault (buffer overflow for win32 only), VLC commit.

VLC Media Player SMB Input Module Buffer Overflow Vulnerability, Secunia

Heise security - http://www.h-online.com/security/Hole-in-V...r--/news/113628

Link to post
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

Loading...