Latest VLC version has dangerous hole

  • 4 February 2013
  • 0 replies
  • 287 views

Userlevel 7
The developers of the VLC video player have warned of a crashing bug in the latest 2.0.5 version of the application, which might be exploited to execute arbitrary code. The issue is a problem in the ASF demuxer (libasf_plugin.*), which can be tricked into overflowing a buffer with a specially crafted ASF movie. The developers note that users would have to open that specially crafted file to be vulnerable and advise users to not open files from untrusted third parties or untrusted sites.
 
More to read in this article.

0 replies

Be the first to reply!

Reply