VideoLAN Arbitrary File Overwrite And Other Abuses Through M3U Parser
22 Apr. 2012
Summary
If successful, a malicious third party could misuse the Stream Output features of VLC media player's the M3U Playlist Parser to write arbitrary data to any accessible file system locations, send packets on the network, etc.
Credit:
The information has been provided by Damien Fouilleul and Remi Denis-Courmont..
Vulnerable Systems:
* VLC media player 0.8.6c and earlier
Using VLC media player's M3U Playlist Parser could lead to arbitrary file overwrite and other unwanted action within the security context of the user running VLC.
Vendor Status:
VideoLAN had issued an update for this vulnerability