News
Contributed by: Lauren Gerber
Date: June 26, 2009
One of my favorite pastimes, especially in winter, is watching movies on my computer. I have a huge movie and music collection and spend lots of time choosing what I want to watch. I truly enjoy watching series and some of them are highly addictive. The multimedia player which I use to play my movies on, is none other than the VLC Media Player. Unfortunately for me and many other VLC Media Player fans, a buffer overflow vulnerability has recently been discovered in the program. The vulnerability in VLC Media Player is caused by a boundary error that exists within the "Win32AddConnection()" function in modules/access/smb.c. The main problem with this vulnerability lies within the factor that, if exploited successfully, it may result in a stack based buffer overflow. This could occur simply by manipulating a VLC Media Player user into opening a file in the playlist which contains an extremely long:"smb://" URI. VLC Media Player is open source and designed by VideoLAN project. It is a fantastic free software, a very portable multimedia player that is geared for a vast variety of video and audio formats. The VLC Media Player is compatible with the majority of operating systems with the inclusion of most Windows versions. Users should know that if this vulnerability is executed effectively and with the correct precision, the chances are very high that it may also allow for the execution of arbitrary code and illegal system access. It is important for VLC Media Player fans to know that this specific vulnerability has a tendency to only affect Windows builds at this current point in time. Makes you think of changing your multimedia player right? Well, some people prefer to make use of the Windows Media Player. A few of the files related to Windows Media Player may include bit are not limited to the following: 7bdf02b635cc942381f3db3f0fe9..., po2_9c84b74ca66444bd8a157120..., wmp10_wmpband.dll, wmp10_wmplayer.exe as well as wmp10_wmploc.dll.
This vulnerability has unfortunately been rated as highly critical. The VLC Media Player vulnerability has been confirmed in versions 0.9.9. It is however crucial for all users to be aware of the fact that the risks are extremely high that other versions are also affected. One way to avoid the exploitation of this vulnerability, is for users to not process any untrusted files with VLC under any circumstances. I hope that you all continue enjoying the wonderful technological aspects that VLC Media Player has to offer. Relax, put your feet up and use VLC Media Player to unwind and de-stress from your day, while you watch a fantastic movie. |
|||||
Software Downloads




User Comments