vendor:
VLC
by:
cuongmx@gmail.com and Look2Me @
7.5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: VLC
Affected Version From: 0.8.6c
Affected Version To: 0.8.6e
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows XP Pro SP2
2009
VLC <= 0.8.6c,e buffer-overflow
This exploit is a local buffer overflow exploit for VLC versions 0.8.6c and 0.8.6e. It creates a .ssa file which contains a header, shellcode, NOP sled, and an AVI file. When the .ssa file is opened with VLC, the shellcode is executed, which in this case is a calculator. The exploit was created by cuongmx@gmail.com and Look2Me @ and tested on Windows XP Pro SP2.
Mitigation:
Update to the latest version of VLC.