VideoLAN VLC axvlc.dll ActiveX Control Multiple Memory Corruption Vulnerabilities
BID:26675
Info
VideoLAN VLC axvlc.dll ActiveX Control Multiple Memory Corruption Vulnerabilities
| Bugtraq ID: | 26675 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2007-6262 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 30 2007 12:00AM |
| Updated: | Dec 13 2007 03:32AM |
| Credit: | Ricardo Narvaja (Ricnar) is credited with the discovery of these vulnerabilities. |
| Vulnerable: |
VideoLAN VLC media player 0.8.6 VideoLAN VLC media player 0.8.6c VideoLAN VLC media player 0.8.6b VideoLAN VLC media player 0.8.6a |
| Not Vulnerable: |
VideoLAN VLC media player 0.8.6 d |
Discussion
VideoLAN VLC axvlc.dll ActiveX Control Multiple Memory Corruption Vulnerabilities
VideoLAN VLC media player is prone to multiple memory-corruption vulnerabilities.
Successfully exploiting these issues allow remote attackers to execute arbitrary code in the context of the application using the affectecd ActiveX control (typically Internet Explorer). Failed exploit attempts will likely result in denial-of-service conditions.
These issues affect VLC media player 0.8.6 to 0.8.6c.
VideoLAN VLC media player is prone to multiple memory-corruption vulnerabilities.
Successfully exploiting these issues allow remote attackers to execute arbitrary code in the context of the application using the affectecd ActiveX control (typically Internet Explorer). Failed exploit attempts will likely result in denial-of-service conditions.
These issues affect VLC media player 0.8.6 to 0.8.6c.
Exploit / POC
VideoLAN VLC axvlc.dll ActiveX Control Multiple Memory Corruption Vulnerabilities
An attacker can exploit these issues by enticing an unsuspecting victim to view a malicious HTNL page.
The following proof-of-concept code is available:
An attacker can exploit these issues by enticing an unsuspecting victim to view a malicious HTNL page.
The following proof-of-concept code is available:
Solution / Fix
VideoLAN VLC axvlc.dll ActiveX Control Multiple Memory Corruption Vulnerabilities
Solution:
The vendor has released an update to address these issues. Please see the references for more information.
VideoLAN VLC media player 0.8.6a
VideoLAN VLC media player 0.8.6c
VideoLAN VLC media player 0.8.6b
VideoLAN VLC media player 0.8.6
Solution:
The vendor has released an update to address these issues. Please see the references for more information.
VideoLAN VLC media player 0.8.6a
-
VideoLAN vlc-0.8.6d-win32.exe
http://www.videolan.org/mirror.html?mirror=http://downloads.videolan.o rg/pub/videolan/&file=vlc/0.8.6d/win32/vlc-0.8.6d-win32.exe
VideoLAN VLC media player 0.8.6c
-
VideoLAN vlc-0.8.6d-win32.exe
http://www.videolan.org/mirror.html?mirror=http://downloads.videolan.o rg/pub/videolan/&file=vlc/0.8.6d/win32/vlc-0.8.6d-win32.exe
VideoLAN VLC media player 0.8.6b
-
VideoLAN vlc-0.8.6d-win32.exe
http://www.videolan.org/mirror.html?mirror=http://downloads.videolan.o rg/pub/videolan/&file=vlc/0.8.6d/win32/vlc-0.8.6d-win32.exe
VideoLAN VLC media player 0.8.6
References
VideoLAN VLC axvlc.dll ActiveX Control Multiple Memory Corruption Vulnerabilities
References:
References:
- Microsoft Knowledge Base Article 240797 (Microsoft)
- VLC Homepage (VideoLAN)
- CORE-2007-1004: VLC Activex Bad Pointer Initialization Vulnerability (CORE Security Technologies Advisories
) - Security Advisory 0703 (VideoLAN)