VLC Media Player Multiple Vulnerabilities
Vulnerabilità:Altamente critica
Where:From remote
Impact:System access
Solution Status:Vendor Workaround
Description
Multiple vulnerabilities have been reported in VLC Media Player, which can be exploited by malicious people to compromise a user's system.
1) An error within the decomp stream filter can be exploited to cause a heap-based buffer overflow.
2) An error within updater can be exploited to cause a buffer overflow.
3) An error within the schroedinger encoder can be exploited to cause a buffer overflow.
4) An error within the mp4 demuxer when parsing string boxes can be exploited to cause a buffer overflow.
5) An error when streaming ogg vorbis files via rtp can be exploited to corrupt memory via an ogg vorbis file containing an overly long "configuration" string.
Successful exploitation of the vulnerabilities may allow execution of arbitrary code.
The vulnerabilities are reported in version 2.1.5. Other versions may also be affected.
Solution:
Fixed in the GIT repository.
----------------------------------------------------------------------------
La 2.1.6 al momento non sembra ancora disponibile
Changes between 2.1.5 and 2.1.6:
--------------------------------
Audio output:
* Fix OSS stuttering
Security:
* Fix heap overflow in decomp stream filter
* Fix buffer overflow in updater
* Fix potential buffer overflow in schroedinger encoder
* Fix null-pointer dereference in DMO decoder
* Fix buffer overflow in parsing of string boxes in mp4 demuxer
Win32 installer:
* Update translations and greek encoding