New security hole in VLC video player
Submitted by srlinuxx on Fri, 08/29/2008 - 06:07.
A new critical security hole has been found in the VLC player from the VideoLan project, while there is still no public fix for the previous security hole found two weeks ago.
The new vulnerability has been found in the handling of mmst:// URLs. If a user opens a URL of this form that points to an attacker's server, the server can deliver crafted data that will cause a buffer overflow on the heap, which could lead to remote code execution, according to a advisory note from Orange Bat.


Recent comments
1 hour 48 min ago
6 hours 31 min ago
9 hours 29 min ago
9 hours 30 min ago
20 hours 46 min ago
1 day 1 min ago
1 day 12 hours ago
1 day 14 hours ago