In association with heise online

20 June 2007, 17:32

VideoLAN executes code from media files

  • Twitter
  • Facebook
  • submit to slashdot
  • StumbleUpon
  • submit to reddit

The developers of the open-source VideoLAN Client (VLC) software have released Version 0.8.6c, which eliminates some vulnerabilities when playing back crafted media files. They explain in a security report that the support modules for the formats Ogg Vorbis and Theora, CD Digital Audio (CDDA) and for the Service Announce Protocol (SAP), contain so-called format string vulnerabilities.

This can allow crafted .ogg/.ogm files, crafted CDDB entries and, for example, network packets in the Service Announce Protocol/Service Discovery Protocol sent to the broadcast address of a local net, to inject malicious program code, which can then be executed with user privileges. The VLC programmers therefore classify the vulnerabilities as critical and recommend updating the installed version with the current Version 0.8.6c.

See also:

(mba)

Print Version | Send by email | Permalink: http://h-online.com/-733095
 


  • July's Community Calendar





The H Open

The H Security

The H Developer

The H Internet Toolkit