VLC Media Player '. m2v' File Memory Corruption Vulnerability
Release date:
Updated on:
Affected Systems:
VideoLAN VLC Media Player 2.1.5
Description:
Bugtraq id: 72106
CVE (CAN) ID: CVE-2014-9598
VLC Media Player is a multimedia Player.
VLC Media Player 2.1.5 does not effectively filter user input. When processing constructed m2v files, a security vulnerability is triggered, causing independent context attackers to destroy the memory and execute arbitrary code.
<* Source: Veysel hatas
Link: http://seclists.org/fulldisclosure/2015/Jan/72
*>
Suggestion:
Vendor patch:
VideoLAN
--------
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Http://www.videolan.org/
Install the latest version of VLC2.0.2 on Ubuntu 12.04
How to install VLC 2.2.0 on Ubuntu 14.04
Ubuntu 14.04 tips: display notifications of VLC (VLC media player)
For details about VLC media player, click here
VLC media player: click here
This article permanently updates the link address: