Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Up and Running » Security » Security » VLC Media Player Vulnerability
Search Topic:
Uniqs:
520
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
Using AVG to scan Gmail E-mail in Outlook »
« Secure LAN File Sharing  
AuthorAll Replies


SpannerITWks
Premium
join:2005-04-22

VLC Media Player Vulnerability

VLC Media Player udp:// Format String Vulnerability

A format string vulnerability exists in the handling of the udp:// URL handler. By supplying a specially crafted string, a remote attacker could cause an arbitrary code execution condition, under the privileges of the user running VLC.

etc -

hxxp://projects.info-pull.com/moab/MOAB-02-01-2007.html

Spanner
--
I Only Know What I Know, But I'm Learning all The Time - Stay Safe - Spanner intheWorks
/SpannerITWks


AB
Premium
join:2006-04-04
Leesburg, VA

Yeah, Quicktime 7.1.3, too.
The big kick-off to the highly anticipated "Month of Apple Bugs" festivities.
Welcome aboard, Mac mateys!

The exploit in QT has to do with RTSP (Real Time Streaming Protocol handler), and the suggested work-around is simply to disable it in QT's preferences.
It affects QT Alternative, also.

What's in store for tomorrow, I wonder?
It's like an old Saturday matinee cliffhanger-- stay tuned!


Dude111
An Awesome Dude
Premium
join:2003-08-04
USA
 reply to SpannerITWks
Anyone have a Proof of Concept Test File for this? (Like to test mine and see)


La Luna
Surviving Ashraful
Premium
join:2001-07-12
Warwick, NY
clubs:
·Optimum Online
·Vonage

reply to SpannerITWks
There is a patch for OS X and Quicktime already.

Update

The developers of VLC meanwhile have included a patch in their CVS. Landon Fuller, maintainer of macports, provides a patch in source and binary form. In addition he also provides an unofficial patch for the Quicktime hole, published yesterday. But you'll need to install the free Application Enhancer to use those binary patches.


»www.heise-security.co.uk/news/83123
--
~~Well, I think you're crazy, I think you're crazy, I think you're crazy, just like me...~~



La Luna
Surviving Ashraful
Premium
join:2001-07-12
Warwick, NY
clubs:
·Optimum Online
·Vonage

reply to Dude111
said by Dude111 See Profile :

Anyone have a Proof of Concept Test File for this? (Like to test mine and see)
»projects.info-pull.com/moab/MOAB···007.html
--
~~Well, I think you're crazy, I think you're crazy, I think you're crazy, just like me...~~



Khaine

join:2003-03-03
Australia
reply to SpannerITWks
This only occurs if VLC is the default player for the stream, or you elect for vlc to open the stream, correct?


Dude111
An Awesome Dude
Premium
join:2003-08-04
USA
·Time Warner VOIP

reply to La Luna
quote:
»projects.info-pull.com/moab/MOAB···007.html
I meant like a link to an actual stream like this test stream I posted for the WMP test in this thread.


ZZZZZZZ
Premium
join:2001-05-27
PARADISE

1 edit
 reply to Khaine
This is only for ''UDP/RTP''........wth uses that anyway!

»secunia.com/advisories/23592/
--
BRING OUR TROOPS HOME,NOW!!!!!


AB
Premium
join:2006-04-04
Leesburg, VA

said by ZZZZZZZ See Profile :

This is only for ''UDP/RTP''........wth uses that anyway!
Me, for one. Not often, but I have used it. Not in VLC, though.


antiserious
The Future ain't what it used to be
Premium
join:2001-12-12
Scranton, PA
reply to SpannerITWks
More info at their site, and a patch is already available.

»www.videolan.org/sa0701.html

--
"The future ain't what it used to be." - Yogi Berra
Forums » Up and Running » Security » SecurityUsing AVG to scan Gmail E-mail in Outlook »
« Secure LAN File Sharing  


Friday, 04-Dec 02:20:43 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.republican-creole
page compression OFF
Most commented news this week
· [162] Comcast Releasing Promised Usage Meter
· [140] Avast Antivirus Has Gone Mad
· [104] Graduate Student Unveils Sprint's GPS Sharing With Feds
· [99] Comcast Makes NBC Universal Acquisition Official
· [85] Google Invades ISP, OpenDNS Turf With Google Public DNS
· [81] Latest Consumer Reports Survey Not Kind To AT&T
· [70] Baltimore To Ban Lazy Cable Installs
· [65] Sprint Defuses GPS Privacy Media Bomb
· [64] Broadband Killed The Game Console
· [58] FCC Ponders Moving From PSTN To IP Voice
Most people now reading
· False positive in Avast! or is it real? [Security]
· Linux is terrorist - according to MS... [All Things Unix]
· [Business] how to bridge a smc 8014 business class modem [Comcast HSI]
· Maximizing Rogue DPS for ToC/ToGC (3.x) [World of Warcraft]
· [Rant] Disrespect of PTO [Rants, Raves, and Praise]
· Heating - my dad gave me this advice... [Home Repair & Improvement]
· Usenet Services- Clarification [TekSavvy]
· [ Classes] Warlock Thread [World of Warcraft]
· Connecting to Google Voice Via SIP [VOIP Tech Chat]
· [TWC] Audio/Video outage in Brooklyn [Time Warner Cable TV/Voice]