Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
TRENDING TODAY
Home > News > Security > Security Blog

June 29th, 2012, 11:29 GMT · By

BLOG

Remote DOS Vulnerability Addressed in VLC 2.0.2

SHARE:

Adjust text size:


Three bugs addressed in VLC 2.0.2 Enlarge picture - Three bugs addressed in VLC 2.0.2
VLC media player 2.0.2 has been released and the list of improvements is fairly long. From a security standpoint, one of the most important changes is the update made to the taglib library.

In VLC 2.0.1, taglib contains a vulnerability (CVE-2012-2396) that could allow a remote attacker to cause a denial-of-service (DOS) state and crash the application via a cleverly crafted .mp4 file.

In order for this flaw to be exploited, an attacker has to convince the victim to open a malicious file via VLC, but as we saw in the past, this doesn’t represent a problem for determined cybercriminals.

The latest variant also addresses an Ogg heap buffer overflow, and updates the libavacodec and other codec libraries.

Since the DOS vulnerability could pose a serious threat, we advise users to immediately update to the latest version.

VLC for Windows is available for download here
VLC for Mac is available for download here
VLC for Linux is available for download here
FILED UNDER:
security update
VLC
DOS

TELL US WHAT YOU THINK:

1,184 hits · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Zemra DDOS Crimeware Kit Used to Extort Organizations

Malware Authors Upgrade Exploit Kits to Randomly Generate Domains

Security Firm: Apple Is Trying to Downplay the Importance of a Flaw in QuickTime

Exploit for Remote Code Execution Flaw in Internet Explorer Released

DHS Investigates Malicious Activity on Hospital Equipment Supplier’s Sites

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2013 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM