VLC Media Player CUE File Buffer Overflow Vulnerability
BID:36403
Info
VLC Media Player CUE File Buffer Overflow Vulnerability
| Bugtraq ID: | 36403 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 15 2009 12:00AM |
| Updated: | Oct 07 2009 06:49PM |
| Credit: | Dr_IDE |
| Vulnerable: |
VideoLAN VLC media player 0.9.5 VideoLAN VLC media player 0.9.4 VideoLAN VLC media player 0.9.3 VideoLAN VLC media player 0.9.2 VideoLAN VLC media player 0.9.1 VideoLAN VLC media player 0.9 VideoLAN VLC media player 0.8.6 i VideoLAN VLC media player 0.8.6 h VideoLAN VLC media player 0.8.6 g VideoLAN VLC media player 0.8.6 d VideoLAN VLC media player 0.8.6 VideoLAN VLC media player 0.8.6f VideoLAN VLC media player 0.8.6e VideoLAN VLC media player 0.8.6c VideoLAN VLC media player 0.8.6b VideoLAN VLC media player 0.8.6a |
| Not Vulnerable: |
VideoLAN VLC media player 0.9.6 |
Discussion
VLC Media Player CUE File Buffer Overflow Vulnerability
VLC media player is prone to a buffer-overflow vulnerability because the WAV file decoder fails to perform adequate boundary checks on user-supplied input.
Attackers may leverage this issue to execute arbitrary code in the context of the application. Failed attacks will cause denial-of-service conditions.
Versions prior to VLC media player 0.9.6 are vulnerable.
VLC media player is prone to a buffer-overflow vulnerability because the WAV file decoder fails to perform adequate boundary checks on user-supplied input.
Attackers may leverage this issue to execute arbitrary code in the context of the application. Failed attacks will cause denial-of-service conditions.
Versions prior to VLC media player 0.9.6 are vulnerable.
Exploit / POC
VLC Media Player CUE File Buffer Overflow Vulnerability
The following exploit code is available:
The following exploit code is available:
Solution / Fix
VLC Media Player CUE File Buffer Overflow Vulnerability
Solution:
Reports indicate that this issue has been fixed in 0.9.6. Please see the references for more information.
Solution:
Reports indicate that this issue has been fixed in 0.9.6. Please see the references for more information.