what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

VLC Media Player 1.0.5 Heap Overflows And Invalid Memory Access

VLC Media Player 1.0.5 Heap Overflows And Invalid Memory Access
Posted Apr 23, 2010
Site videolan.org

VLC Media Player versions 0.5.0 through 1.0.5 suffer from heap buffer overflow and memory access vulnerabilities.

tags | advisory, overflow, vulnerability
SHA-256 | 7437866dbb5dd04e28279cd9c3748c9ca764743f7a0eccdaac574d71986dd3d8

VLC Media Player 1.0.5 Heap Overflows And Invalid Memory Access

Change Mirror Download
Security Advisory 1003

Summary : Heap buffer overflow vulnerability in A/52, DTS
and MPEG Audio decoders
Invalid memory access in AVI, ASF, Matroska (MKV) demuxers
Invalid memory access in XSPF playlist parser
Invalid memory access in ZIP archive decompressor
Heap buffer overflow in RTMP access
Date : 19 April 2010
Affected versions : VLC media player 1.0.5 down to 0.5.0
ID : VideoLAN-SA-1003
CVE references : N/A (at the time of writing)

Details

VLC media player suffers from various vulnerabilities when attempting to parse malformatted or overly long byte streams.
Impact

If successful, a malicious third party could crash the player instance or perhaps execute arbitrary code within the context of VLC media player.
Threat mitigation

Exploitation of those bugs requires the user to explicitly open specifically crafted malicious files.
Workarounds

The user may refrain from opening files from untrusted sources.
Solution

VLC media player 1.0.6 addresses these issues and introduces further stability fixes.

VLC media player 1.1.0 (currently in pre-release stage) addresses these issues as well and introduces further enhancements and fixes over version 1.0.6.
Credits

These vulnerabilities were discovered by the development team while working on VLC 1.1.0.
References

The VideoLAN Project
http://www.videolan.org/

History

21 April 2010
VLC 1.0.6 bugfix release
Initial advisory

RĂ©mi Denis-Courmont,
on behalf of the VideoLAN project


Login or Register to add favorites

File Archive:

April 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Apr 1st
    10 Files
  • 2
    Apr 2nd
    26 Files
  • 3
    Apr 3rd
    40 Files
  • 4
    Apr 4th
    6 Files
  • 5
    Apr 5th
    26 Files
  • 6
    Apr 6th
    0 Files
  • 7
    Apr 7th
    0 Files
  • 8
    Apr 8th
    22 Files
  • 9
    Apr 9th
    14 Files
  • 10
    Apr 10th
    10 Files
  • 11
    Apr 11th
    13 Files
  • 12
    Apr 12th
    14 Files
  • 13
    Apr 13th
    0 Files
  • 14
    Apr 14th
    0 Files
  • 15
    Apr 15th
    30 Files
  • 16
    Apr 16th
    10 Files
  • 17
    Apr 17th
    22 Files
  • 18
    Apr 18th
    45 Files
  • 19
    Apr 19th
    0 Files
  • 20
    Apr 20th
    0 Files
  • 21
    Apr 21st
    0 Files
  • 22
    Apr 22nd
    0 Files
  • 23
    Apr 23rd
    0 Files
  • 24
    Apr 24th
    0 Files
  • 25
    Apr 25th
    0 Files
  • 26
    Apr 26th
    0 Files
  • 27
    Apr 27th
    0 Files
  • 28
    Apr 28th
    0 Files
  • 29
    Apr 29th
    0 Files
  • 30
    Apr 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close