VLC Media Player '.AMV' and '.NSV' Files Multiple Remote Buffer Overflow Vulnerabilities
BID:47012
Info
VLC Media Player '.AMV' and '.NSV' Files Multiple Remote Buffer Overflow Vulnerabilities
| Bugtraq ID: | 47012 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2010-3275 CVE-2010-3276 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 23 2011 12:00AM |
| Updated: | Mar 19 2015 09:33AM |
| Credit: | Ricardo Narvaja of Core Security Technologies. |
| Vulnerable: |
VideoLAN VLC media player 1.1.7 VideoLAN VLC media player 1.1.6 1 VideoLAN VLC media player 1.1.4 VideoLAN VLC media player 1.1.3 VideoLAN VLC media player 1.1.2 VideoLAN VLC media player 1.1.1 VideoLAN VLC media player 1.1 VideoLAN VLC media player 1.0.6 VideoLAN VLC media player 1.0.5 VideoLAN VLC media player 1.0.3 VideoLAN VLC media player 1.0.2 VideoLAN VLC media player 1.0.1 VideoLAN VLC media player 1.0 VideoLAN VLC media player 0.9.9 VideoLAN VLC media player 0.9.7 VideoLAN VLC media player 0.9.6 VideoLAN VLC media player 0.9.5 VideoLAN VLC media player 0.9.4 VideoLAN VLC media player 0.9.3 VideoLAN VLC media player 0.9.2 VideoLAN VLC media player 0.9.1 VideoLAN VLC media player 0.9 VideoLAN VLC media player 1.1.6 VideoLAN VLC media player 1.1.5 VideoLAN VLC media player 1.1.3 VideoLAN VLC media player 1.1.2 VideoLAN VLC media player 1.1.1 VideoLAN VLC media player 1.1.0 VideoLAN VLC media player 1.0.4 VideoLAN VLC media player 0.9.8a Gentoo Linux Debian Linux 5.0 sparc Debian Linux 5.0 s/390 Debian Linux 5.0 powerpc Debian Linux 5.0 mipsel Debian Linux 5.0 mips Debian Linux 5.0 m68k Debian Linux 5.0 ia-64 Debian Linux 5.0 ia-32 Debian Linux 5.0 hppa Debian Linux 5.0 armel Debian Linux 5.0 arm Debian Linux 5.0 amd64 Debian Linux 5.0 alpha Debian Linux 5.0 |
| Not Vulnerable: |
VideoLAN VLC media player 1.1.8 |
Discussion
VLC Media Player '.AMV' and '.NSV' Files Multiple Remote Buffer Overflow Vulnerabilities
VLC media player is prone to multiple buffer-overflow vulnerabilities.
Attackers can exploit these issues to execute arbitrary code in the context of the affected application or crash the application, denying service to legitimate users.
Versions prior to VLC media player 1.1.8 are vulnerable.
VLC media player is prone to multiple buffer-overflow vulnerabilities.
Attackers can exploit these issues to execute arbitrary code in the context of the affected application or crash the application, denying service to legitimate users.
Versions prior to VLC media player 1.1.8 are vulnerable.
Exploit / POC
VLC Media Player '.AMV' and '.NSV' Files Multiple Remote Buffer Overflow Vulnerabilities
The following MetaSploit exploit module is available:
The following MetaSploit exploit module is available:
Solution / Fix
VLC Media Player '.AMV' and '.NSV' Files Multiple Remote Buffer Overflow Vulnerabilities
Solution:
Reports indicate that these issues have been fixed in the upcoming 1.1.8 release. Please contact the vendor for more information.
Solution:
Reports indicate that these issues have been fixed in the upcoming 1.1.8 release. Please contact the vendor for more information.
References
VLC Media Player '.AMV' and '.NSV' Files Multiple Remote Buffer Overflow Vulnerabilities
References:
References:
- VLC Homepage (VideoLAN)
- CORE-2011-0208: VLC Vulnerabilities handling .AMV and .NSV files (CORE Security Technologies Advisories)