Skip to main content

VLC Media Player Real Demuxer File Handling Array Indexing Vulnerability

Last Update Date: 28 Jan 2011 Release Date: 4 Jan 2011 5102 Views

RISK: Medium Risk

A vulnerability has been identified in VLC Media Player, which could be exploited by attackers to execute arbitrary code. This issue is caused by an array indexing error in the "Close()" and "DemuxAudioMethod1()" [modules/demux/real.c] functions within the Real demuxer when processing a Real Media file with a zero "i_subpackets" value, which could be exploited by attackers to crash an affected application or compromise a vulnerable system by convincing a user to open a malicious media file or to visit a specially crafted web page.


Impact

  • Remote Code Execution

System / Technologies affected

  • VLC Media Player version 1.1.5 and prior

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.


Vulnerability Identifier


Source


Related Link