|
Brought to you by:
Suppliers of:
|
|
|
| |
| "VLC media player is a highly portable multimedia player for various audio and video formats (MPEG-1, MPEG-2, MPEG-4, DivX, mp3, ogg, ...) as well as DVDs, VCDs, and various streaming protocols." Secunia Research has discovered a vulnerability in VLC Media Player, which can be exploited by malicious people to compromise a user's system. |
| |
Credit:
The information has been provided by Secunia Research.
The original article can be found at: http://secunia.com/secunia_research/2008-29/
|
| |
Vulnerable Systems:
* VLC Media Player version 0.8.6h (Windows)
Immune Systems:
* VLC Media Player version 0.8.6i
The vulnerability is caused due to an integer overflow error within the "Open()" function in modules/demux/wav.c. This can be exploited to cause a heap-based buffer overflow via a specially crafted WAV file having an overly large "fmt" chunk.
Successful exploitation may allow execution of arbitrary code.
Time Table:
27/06/2008 - Vendor notified.
30/06/2008 - Vendor response.
02/07/2008 - Public disclosure.
CVE Information:
CVE-2008-2430
|
|
|
|
|