vendor:
VLC
by:
k`sOSe
7.5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: VLC
Affected Version From: VLC 0.9.4
Affected Version To: VLC 0.9.4
Patch Exists: YES
Related CWE: N/A
CPE: a:videolan:vlc:0.9.4
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2008
Rewritten VLC 0.9.4 .TY File Buffer Overflow Exploit
This exploit is a buffer overflow vulnerability in VLC 0.9.4. It works on Windows XP SP1, SP2, SP3 and probably Win2k. It works both with a local file and with a remote URL. The exploit does not crash VLC, and it allows for a respawning shell even if VLC is closed.
Mitigation:
Update to the latest version of VLC.