vendor:
VLC Player
by:
Kevin Finisterre
7.5
CVSS
HIGH
Format String
Unknown
CWE
Product Name: VLC Player
Affected Version From: Unknown
Affected Version To: Unknown
Patch Exists: NO
Related CWE: Unknown
CPE: Unknown
Platforms Tested: OSX
2007
VLCMediaSlayer-ppc.pl Format String Exploit
This is a vanilla format string exploit for VLC Player on OSX for PowerPC (ppc) architecture. The exploit overwrites a saved return address with a shellcode address. The exploit creates a malicious .m3u file that when executed by VLC Player, executes arbitrary code.
Mitigation:
Unknown