>> VideoLAN VLC "cdio_log_handler()" and "vcd_log_handler()" Format String Vulnerabilities
Title : VideoLAN VLC "cdio_log_handler()" and "vcd_log_handler()" Format String Vulnerabilities VUPEN ID : VUPEN/ADV-2007-0026 CVE ID : CVE-2007-0017
Rated as : Critical
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2007-01-03
Technical Description
Multiple vulnerabilities have been identified in VideoLAN VLC, which could be exploited by attackers to take complete control of an affected system. These issues are due to format string errors in the "cdio_log_handler()" and "vcd_log_handler()" functions that call "msg_Dbg()", "msg_Warn()", and "msg_Err()" in an insecure manner, which could be exploited by remote attackers to execute arbitrary commands by tricking a user into visiting a specially crafted web page or opening a malicious M3U playlist.