Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
TRENDING TODAY
Home > News > Security > Security Blog

January 31st, 2013, 09:05 GMT · By

BLOG

Buffer Overflow Vulnerability Identified in VLC 2.0.5 and Earlier

SHARE:

Adjust text size:


Buffer overflow vulnerability found in VLC player Enlarge picture - Buffer overflow vulnerability found in VLC player
Security researcher Debasish Mandal has identified a buffer overflow vulnerability in the ASF demuxer of the popular VLC media player.

VideoLAN, the company that develops VLC, warns that successful exploitation of the vulnerability can lead to a crash and, possibly, even execution of arbitrary code within the context of the application.

The issue can be exploited if the attacker convinces the user to open a specially crafted ASF file.

VLC media player 2.0.5 and earlier variants are affected by the security whole.

The flaw will be addressed with the future 2.0.6 release. In the meantime, users are advised to refrain from opening suspicious ASF files.

In addition, customers can disable ASF movie playback altogether by removing the ASF demuxer (libasf_plugin.*) from the VLC plugin directory.

Another solution is to install one of the nightly builds. However, these builds might be unstable and they might not even work at all.

TELL US WHAT YOU THINK:

1,156 hits · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Yahoo! Hack Demonstrates the Risks Posed by Third-Party Code in Cloud Computing

Over 40 Million Devices Vulnerable to Attacks Because of Universal Plug and Play Flaws

PayPal Rewards Researcher for Finding Blind SQL Injection Flaw on Notifications Site

Experts Find Vulnerabilities in nCircle PureCloud Security Scanner

Ruby on Rails 3.0.20 and 2.3.16 Released to Address Extremely Critical Vulnerability

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2013 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM