Skip to main content

VLC Media Player "MP4_ReadBox_skcr()" Heap Corruption Vulnerability

Last Update Date: 19 Apr 2011 Release Date: 12 Apr 2011 5124 Views

RISK: Medium Risk

TYPE: Clients - Audio & Video

TYPE: Audio & Video

A vulnerability has been identified in VLC Media Player, which could be exploited by remote attackers to compromise a vulnerable system. This issue is caused by a heap corruption error in the "MP4_ReadBox_skcr()" [modules/demux/mp4/libmp4.c] function when processing malformed MP4 (MPEG-4 Part 14) data, which could be exploited by remote attackers to execute arbitrary code by tricking a user into opening a malicious file or visiting a specially crafted web page.


Impact

  • Remote Code Execution

System / Technologies affected

  • VLC Media Player version 1.1.8 and prior

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.


Vulnerability Identifier

  • No CVE information is available

Source


Related Link