View Single Post
Old 03-19-2008, 07:05 AM   #1 (permalink)
Osiris
Security/Hacking Mod
 
Osiris's Avatar
 
Join Date: Jan 2005
Location: USA
Posts: 24,120
Default VLC Player Vulnerability

Torrentfreak are reporting that two vulnerabilities have been discovered in VLC Player which allow execution of arbitrary code. The second vulnerability has already been fixed in the newest version of VLC which is available for download on the developers homepage. The first vulnerability however can be exploited to cause stack-based buffer overflows when loading subtitles in VLC.
The solution given by the security company that discovered the vulnerability is to load only subtitles from trusted source or no subtitles at all until an official fix has been posted by the developers ov VLC.
Another option would be to switch to another player for the time being. SMPlayer, my favorite player, is another good choice which does not have this vulnerability.

VLC Player Vulnerability
Osiris is online now   Reply With Quote