|
|
| |
| If successful, a malicious third party could crash the player instance or perhaps execute arbitrary code within the context of VLC media player. |
| |
Credit:
|
| |
Vulnerable Systems:
* VLC media player 1.0.5 down to 0.5.0
VLC media player suffers from various vulnerabilities when attempting to parse malformatted or overly long byte streams.
Vendor Status:
VideoLAN had issues an update for this vulnerability
Patch Availability:
http://www.videolan.org/security/sa1003.html
CVE Information:
CVE-2010-1441
Disclosure Timeline:
28 April 2010
CVE numbers assigned
21 April 2010
VLC 1.0.6 bugfix release
Initial advisory
|
|
blog comments powered by
|