>> VideoLAN VLC Media Player ActiveX Plugin and FLAC Code Execution
Title : VideoLAN VLC Media Player ActiveX Plugin and FLAC Code Execution VUPEN ID : VUPEN/ADV-2007-4061 CVE ID : CVE-2007-4619 - CVE-2007-6262
Rated as : Critical
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2007-12-03
Technical Description
Multiple vulnerabilities have been identified in VideoLAN VLC Media Player, which could be exploited by remote attackers to cause a denial of service or compromise a vulnerable system.
The first issue is caused by errors in the VLC ActiveX plugin, which could be exploited by malicious web sites to overwrite arbitrary memory zones and execute malicious code.
The second vulnerability is caused by errors in Flac. For additional information, see : VUPEN/ADV-2007-3483