Release date: 2012-03-19
Updated on: 2012-03-20
Affected Systems:
VideoLAN VLC Media Player 2.x
Description:
--------------------------------------------------------------------------------
Bugtraq id: 52550
VLC Media Player is a multimedia Player named VideoLAN client.
VLC Media Player has multiple implementation vulnerabilities that malicious users can exploit to control user systems.
1) The "MMSOpen ()" function (modules/access/MMS/mmstu) of the mms access Plug-in (libaccess_mms_plugin. c) There is a boundary error. stack buffer overflow can be caused by a specially crafted MMS stream;
2) when processing Real rtsp streams, there is an error in the realrtsp access plug-in, which can be exploited to cause heap buffer overflow.
<* Source: Florent Hochwelker aka TaPiOn
Link: http://secunia.com/advisories/48500/
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
VideoLAN
--------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.videolan.org/