If successful, a malicious third party could crash the VLC media player process. Arbitrary code execution might be possible on some systems, though this is unconfirmed.
Credit:
The information has been provided by Clement Lecigne.
Vulnerable Systems:
* VLC media player 1.1.12 down to 0.9.0
The user should refrain from opening files from untrusted third parties or accessing untrusted remote sites (or disable the VLC browser plugins), until the patch is applied. Alternatively, the TY demux plugin (libty_plugin.*) can be removed manually from the VLC plugin installation directory. This will prevent opening of TiVo files.
Vendor Status:
VideoLAN had issues an update for this vulnerability