Release date:
Updated on:
Affected Systems:
VideoLAN VLC Media Player 1.1.x
VideoLAN VLC Media Player 0.9.x
Unaffected system:
VideoLAN VLC Media Player 1.1.13
Description:
--------------------------------------------------------------------------------
Bugtraq id: 51231
Cve id: CVE-2012-0023
VLC Media Player is a multimedia Player named VideoLAN client.
When the VLC Media Player parses the header of an invalid TY file, a heap buffer overflow vulnerability exists in the implementation of TiVo demuxer. After successful exploitation, attackers can execute arbitrary code in the application, causes the VLC Media Player process to crash.
<* Source: Clement Lecigne
Link: http://www.videolan.org/security/sa1108.html
*>
Suggestion:
--------------------------------------------------------------------------------
Temporary solution:
Do not open suspicious files or access suspicious remote sites before applying patches;
You can also manually delete the TY demux plug-in (libty_plugin. *) from the VLC plug-in installation directory .*).
Vendor patch:
VideoLAN
--------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.videolan.org/