If successful, a malicious third party could crash the player instance. Arbitrary code execution within the context of VLC media player might be possible, though it was unconfirmed.
Credit:
The information has been provided by Hossein Lotfi .
Vulnerable Systems:
* VLC media player 1.1.10 down to 1.1.0
The user may refrain from opening files from untrusted sources. Alternatively, the RealMedia plugin (demux/libreal_plugin.*) can be removed. This will however prevent use of any of Real Media files.
Vendor Status:
VideoLAN had issues an update for this vulnerability