|
|
|
|
| |
Credit:
The information has been provided by Kevin Finisterre.
|
| |
Vulnerable Systems:
* VLC media player 0.8.6 down to 0.7.0
VLC media player CDDA (CD Digital Audio) and VCDX (Video CD) plugins are prone to a C-style format string vulnerability when trying to open a media resource location. The bug occurs when handling error and debug messages from underlying library libcdio.
Because the VCDX plugins probes every media resource location unless another plugin successfully opened the resource, almost any invalid location can trigger the bug.
Vendor Status:
VideoLAN had issued an update for this vulnerability
Patch Availability:
http://www.videolan.org/security/sa0702.html
CVE Information:
CVE-2007-0017
Disclosure Timeline:
05 January 2007
Added CVE candidate ID reference
04 January 2007
VLC 0.8.6a bugfix release
Binaries for Windows and MacOS X
03 January 2007
Initial advisory
Patch provided against VLC 0.8.6 source code
02 January 2007
Patch applied to VLC development tree
Bug reported and publicized by Kevin Finisterre
|
|
|
|
|