vendor:
VLC Media Player
by:
SkD
7.5
CVSS
HIGH
Buffer Overflow
Unknown
CWE
Product Name: VLC Media Player
Affected Version From: 0.9.6 and earlier
Affected Version To: 2000.9.6
Patch Exists: NO
Related CWE: Unknown
CPE: Unknown
Platforms Tested: Windows XP SP3
Unknown
VLC Media Player < 0.9.6 .RT File Buffer Overflow (Stack Based)
This exploit targets a buffer overflow vulnerability in the VLC Media Player version 0.9.6 and earlier. By exploiting this vulnerability, an attacker can execute arbitrary code on a target system. The exploit requires a 'jmp esp' address in one of the DLLs loaded with VLC. This specific exploit is designed to work on a fully up-to-date Windows XP SP3 system. The author does not take responsibility for any damage caused by using this exploit.
Mitigation:
Update to a version of VLC Media Player that is not vulnerable to this buffer overflow.