Core Security
info@coresecurity.com  | +1.617.399.6980 | Contact Us   Core Blog Core Blog Twitter LinkedIn youtube
SHARE

CORE IMPACT v7.5 - Exploits Update (Thu Jan 03 2008)

VideoLAN VLC buffer overflow subtitle exploit

Exploits/Client Side  [Windows]




• Thu Jan 03 2008
VLC is able to handle the subtitles automatically in a very simple way, it just checks the presence of ssa files with the same name of the loaded video and a possible subtitles folder. The functions which handle the MicroDvd, SSA and Vplayer subtitle formats are vulnerable to some stack based buffer-overflow vulnerabilities which can allow an attacker to execute malicious code.

Exploits Vulnerabiltiy: CVE-9999-2040



< Back to Product Updates