Vulnerable Systems:
* VLC media player 0.9.5 down to 0.5.0
The user should refrain from opening files from untrusted third parties or accessing untrusted remote sites (or disable the VLC browser plugins), until the patch is applied.
Alternatively, the VCD and Subtitles plugins (libvcd_plugin.* and libsubtitle_plugin.*) can be removed manually from the VLC plugin installation directory. However, this will prevent use of subtitle files and Video CD altogether.
Vendor Status:
VideoLAN had issued an update for this vulnerability
Disclosure Timeline:
3 November 2008 Vendor notification.
4 November 2008 Internal patches for VLC development version and 0.9-bugfix tree.
5 November 2008 Initial security advisory. VLC media player 0.9.6 released.