vendor:
VLC Media Player
by:
Pankaj Kohli
9,3
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: VLC Media Player
Affected Version From: 0.8.6f
Affected Version To: 0.8.6f
Patch Exists: YES
Related CWE: N/A
CPE: a:videolan:vlc_media_player
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows XP SP3
2009
VLC Media Player ‘smb://’ URI Handling Remote Buffer Overflow Vulnerability Exploit
VLC Media Player is prone to a remote buffer-overflow vulnerability because it fails to properly bounds-check user-supplied data before copying it into an insufficiently sized memory buffer. An attacker can exploit this issue to execute arbitrary code in the context of the application. Failed exploit attempts will result in a denial-of-service condition.
Mitigation:
Upgrade to the latest version of VLC Media Player.