VLC Media Player Read Access Violation Arbitrary Code Execution Vulnerability
BID:55850
Info
VLC Media Player Read Access Violation Arbitrary Code Execution Vulnerability
| Bugtraq ID: | 55850 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2012-5470 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 10 2012 12:00AM |
| Updated: | Nov 10 2014 12:58AM |
| Credit: | Jean Pascal Pereira |
| Vulnerable: |
Gentoo Linux |
| Not Vulnerable: | |
Discussion
VLC Media Player Read Access Violation Arbitrary Code Execution Vulnerability
VLC Media Player is prone to an arbitrary code-execution vulnerability.
Successful exploits may allow an attacker to execute arbitrary code within the context of the user running the affected application.
VLC Media Player 2.0.3 and prior are vulnerable.
VLC Media Player is prone to an arbitrary code-execution vulnerability.
Successful exploits may allow an attacker to execute arbitrary code within the context of the user running the affected application.
VLC Media Player 2.0.3 and prior are vulnerable.
Exploit / POC
VLC Media Player Read Access Violation Arbitrary Code Execution Vulnerability
The following proof-of-concept is available:
The following proof-of-concept is available:
Solution / Fix
VLC Media Player Read Access Violation Arbitrary Code Execution Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
References
VLC Media Player Read Access Violation Arbitrary Code Execution Vulnerability
References:
References:
- VLC Homepage (VideoLAN)