VideoLAN Insufficient input validation in VLC TagLib plugin
22 Aug. 2010
Summary
In the failure case, VLC will dereference a memory address within the first page of its process virtual memory. In normal conditions, this will result in a segmentation fault (a general protection fault on Windows), and the process will terminate abruptly.
Credit:
The information has been provided by FortiGuard Labs..
Vulnerable Systems:
* VLC media player versions 1.1.2 down to 0.9.0
The user should refrain from opening files from untrusted third parties or accessing untrusted remote sites (or disable the VLC browser plugins), until the patch is applied.
Vendor Status:
VideoLAN had issued an update for this vulnerability