vendor:
VLC Media Player/Kodi/PopcornTime
by:
SivertPL
7.8
CVSS
HIGH
Memory Corruption
119
CWE
Product Name: VLC Media Player/Kodi/PopcornTime
Affected Version From: 2.2.5
Affected Version To: 2.2.5
Patch Exists: YES
Related CWE: CVE-2017-8311
CPE: vlc/kodi/popcorntime
Other Scripts:
N/A
Platforms Tested: Windows
2017
VLC Media Player/Kodi/PopcornTime ‘Red Chimera’ < 2.2.5 Memory Corruption (PoC)
Infamous VLC/Kodi/PopcornTime subtitle attack in libsubtitle_plugin.dll. This is the Proof of Concept of the reverse engineered heap corruption vulnerability affecting JacoSUB parsing in VLC/Kodi/PopcornTime. The crash is exploitable, but hard to exploit because of various environmental constraints such as threading/mitigations/scriptless.
Mitigation:
Apply the latest security patches and updates to the affected software.