Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
TRENDING TODAY
Home > News > Security > Advisories

April 10th, 2008, 07:19 GMT · By

Users of VLC Media Player Should Apply this Patch Immediately!

SHARE:

Adjust text size:

VLC in action
Enlarge picture
VLC Media Player is quite a popular application nowadays, especially because it provides a remarkable functionality bundled with a freeware license. This
means that users are able to take advantage of its applaudable functions without paying for the software, as in the case of other programs on the market.

However, users of older versions of VLC Media Player are urged to update to the latest version of the application because a security flaw has been spotted in these releases. Calling it "VLC Media Player Browser Plugin Arbitrary File Overwrite Vulnerability," the folks of SecurityFocus explained that VLC Media Player 0.8.6, 0.8.6a, 0.8.6b and several edition of the program addressed to Debian Linux are all vulnerable.

The only version not vulnerable to this security flaw is VLC Media Player 0.8.6d which was especially rolled out by VideoLAN to correct the glitch.

"VLC media player is prone to a vulnerability that allows attackers to overwrite arbitrary files.
Successful exploits can compromise the computer or cause denial-of-service conditions. Versions prior to VLC media player 0.8.6d are vulnerable," SecurityFocus explained in the security advisory published on its main page.

At this time, there's no confirmation of a potential successful exploitation of the flaw, but consumers who are currently using older releases of VLC Media Player should update the application as soon as possible.

VLC Media Player supports a large series of formats, starting with 3GP, AVI, QuickTime, WAV and MP3 and ending with AAC, AC3, AMR, FLAC and WMA. Unfortunately, the application can't open or play the files based on RealMedia, Fraps and MIDI codecs.

For those of you who want to download the latest release of VLC Media Player, you can find it right here on Softpedia by clicking on the following link.


6,410 hits · 1 comment
Link to this article · Print article · Send to friend

MUST-READ RELATED ARTICLES:


VLC Player Not Safe!

Ubuntu Weekly Report: 9th - 15th March, 2008

Ubuntu Weekly Report: 13th - 19th January

DesktopBSD 1.6 Available Now

Debian 4.0 Second Release Now Available

READER COMMENTS:


Comment #1 by: Andrew_C on 12 Apr 2008, 23:36 UTC reply to this comment

This is ancient news! VLC 0.8.6d has been out since 30 November 2007. The present version is 0.8.6f

Copyright © 2001-2013 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM