New Zero-Day Vulnerabilities Announced in VLC Media Player

win7holic

New Member
Thread author
Apr 20, 2011
2,079
Two yet-to-be-patched vulnerabilities have been disclosed in VLC media player and can potentially be exploited by attackers to execute arbitrary code.

According to vulnerability research company Secunia, who rates the flaws as highly critical, they affect the third-party libmodplug plugin which is included in VLC.

The vulnerabilities were discovered and disclosed as zero-days complete with proof-of-concept exploit code by a user calling himself epiphant.

"The vulnerabilities are caused due to boundary errors within the 'abc_new_macro()' and 'abc_new_umacro()' functions in src/load_abc.cpp, which can be exploited to cause stack-based buffer overflows by tricking a user into opening specially crafted ABC files," Secunia explains in its advisory.

read more
 

Gnosis

Level 5
Apr 26, 2011
2,779
Hmmm. Maybe that explains my PC's sporadic performances lately, but I run scans like I have schizophrenia, so I doubt I am infected.
 

win7holic

New Member
Thread author
Apr 20, 2011
2,079
MetalShaun said:
Been a lot of VLC ones recently. Thanks for the update.

you're welcome..
here , iwant share news about malware and anything :)
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top