Citation
http://www.videolan....ad-windows.html
Citation
Summary : Format string injection in Vorbis, Theora, SAP
and CDDA plugins
Date : 12 June 2007
Affected versions : VLC media player 0.8.6b and earlier
ID : VideoLAN-SA-0702
CVE reference : not currently available
Details
VLC media player Ogg/Vorbis, Ogg/Theora, CDDA (CD Digital Audio) and SAP (Service Announce Protocol) plugins are prone to a C-style format string vulnerability when trying to parse a media data stream.
Valid but carefully crafted .ogg (Vorbis) or .ogm (Theora) files, CDDB entries or SAP/SDP messages can trigger the bug. We therefore consider this bug to have a high severity.
Impact
If successful, a malicious third party could use this vulnerability to execute arbitrary code within the context of VLC media player (i.e. acquire local user privileges on the vulnerable system), or crash the player instance.
Threat mitigation
Exploitation of this bug requires getting VLC to read a crafted Ogg file, an Audio CD with a crafted CDDB entry. If SAP service discovery is enabled, the bug can be exploited by sending a crafted multicast packets on the network.
...
http://www.videolan.org/sa0702.html
Amicalement.
Ce message a été modifié par horus agressor - 07 juin 2008 - 04:16 .

Aide















