If successful, it is unknown whether a malicious third party might be able to trigger execution of arbitrary code. Successful exploitation of this bug can crash the process of the media player.
Credit:
The information has been provided by Aliz Hammond..
Vulnerable Systems:
* VLC media player 1.1.8 down to 1.0.0
The user should refrain from opening files from untrusted third parties or accessing untrusted remote sites (or disable the VLC browser plugins), until the patch is applied.
Alternatively, the MP4 decoder plugin (libmp4_plugin.*) can be removed manually from the VLC plugin installation directory.
Vendor Status:
VideoLAN had issues an update for this vulnerability
Disclosure Timeline:
7 April 2011 Vendor notified
9 April 2011 Patches published Security advisory published
12 April 2011 VLC media player 1.1.9 released
13 April 2011 CVE ID reserved