vendor:
VLC media player
by:
coolkaveh
7,8
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: VLC media player
Affected Version From: 2.0.4 Twoflower
Affected Version To: 2.0.4 Twoflower
Patch Exists: NO
Related CWE: N/A
CPE: a:videolan:vlc_media_player:2.0.4
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows XP SP3
2012
VLC media player 2.0.4 buffer overflow POC
VLC media player (also known as VLC) is a highly portable free and open-source media player and streaming media server written by the VideoLAN project. It is a cross-platform media player, with versions for Microsoft Windows, OS X, GNU/Linux, Android, BSD, Solaris, iOS, Syllable, BeOS, MorphOS, QNX and eComStation. A buffer overflow vulnerability exists during the handling of the swf file, which can allow attackers to execute arbitrary code.
Mitigation:
Ensure that all user-supplied input is validated and filtered before being used.