The Network Security. Org

RSS Feed

Security holes in VLC media player patched

March 4th, 2008 · No Comments


The developers of the open source media player VLC have closed several security holes. These would have allowed attackers to inject and execute malicious code using manipulated Realtime data streams or crafted video files. The latest version, 0.8.6e, is available to download and fixes the flaws.

According to the VLC programmers’ announcement, the current version no longer contains the error in decoding specially crafted real-time data streams (RTSP), which could cause a heap buffer overflow due to a string validation error. Two additional security holes existed in the subtitle dumuxer and in the user interface, which attackers also could have exploited to inject code. Security holes in VLC media player patched - News - heise Security UK

From around the Web

  • Advertisments