>> VideoLAN VLC Remote Buffer Overflow and Format String Vulnerabilities
Title : VideoLAN VLC Remote Buffer Overflow and Format String Vulnerabilities VUPEN ID : VUPEN/ADV-2007-4308 CVE ID : CVE-2007-6681 - CVE-2007-6682 - CVE-2008-1881
Rated as : Critical
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2007-12-26
Technical Description
Multiple vulnerabilities have been identified in VideoLAN VLC Media Player, which could be exploited by remote attackers to cause a denial of service or compromise a vulnerable system.
The first issue is caused by buffer overflow errors in the "ParseMicroDvd()", "ParseSSA()" and "ParseVplayer()" [modules/demux/subtitle.c] functions when handling subtitles, which could be exploited by attackers to crash a vulnerable application or execute arbitrary code.
The second vulnerability is caused by a format string error in the web interface when processing the "Connection" parameter via the "httpd_FileCallBack()" [network/httpd.c] function, which could be exploited to crash a vulnerable application or execute arbitrary code.