Home→Descriptions→SA48500
| Secunia ID | |
| CVE-ID |
CVE-2011-3026, CVE-2012-1126, CVE-2012-1127, CVE-2012-1128, CVE-2012-1129, CVE-2012-1130, CVE-2012-1131, CVE-2012-1132, CVE-2012-1133, CVE-2012-1134, CVE-2012-1135, CVE-2012-1136, CVE-2012-1137, CVE-2012-1138, CVE-2012-1139, CVE-2012-1140, CVE-2012-1141, CVE-2012-1142, CVE-2012-1143, CVE-2012-1144, CVE-2012-1775, CVE-2012-1776 |
| Release Date |
19 Mar 2012 |
| Last Change |
21 Mar 2012 |
| Criticality | |
| Solution Status |
Vendor Patch |
| Software |
VLC Media Player 2.x |
| Where | |
| Impact |
System accessThis covers vulnerabilities where malicious people are able to gain system access and execute arbitrary code with the privileges of a local user. |
| Description |
Multiple vulnerabilities have been reported in VLC Media Player, which can be exploited by malicious people to compromise a user's system. 1) A boundary error within the "MMSOpen()" function (modules/access/mms/mmstu.c) in the MMS access plugin (libaccess_mms_plugin) can be exploited to cause a stack-based buffer overflow via a specially crafted MMS stream. 2) Some errors within the realrtsp access plugin (libaccess_realrtsp_plugin) when handling Real rtsp streams can be exploited to cause heap-based buffer overflows. 3) The application bundles a vulnerable version of the libpng library. For more information: 4) The application bundles a vulnerable version of the FreeType library. For more information: Successful exploitation of the vulnerabilities may allow execution of arbitrary code. The vulnerabilities are reported in versions prior to 2.0.1. |
| Solution |
Update to version 2.0.1. |
| Reported by |
The vendor credits Florent Hochwelker aka TaPiOn. |
| Original Advisory |
VLC Media Player (VideoLAN-SA-1201, VideoLAN-SA-1202): |