>> VideoLAN VLC Media Player MP4 Demuxer Code Execution Vulnerability
Title : VideoLAN VLC Media Player MP4 Demuxer Code Execution Vulnerability VUPEN ID : VUPEN/ADV-2008-0682 CVE ID : CVE-2008-0984
Rated as : Critical
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2008-02-27
Technical Description
A vulnerability has been identified in VideoLAN VLC Media Player, which could be exploited by remote attackers to cause a denial of service or take complete control of an affected system. This issue is caused by a memory overwrite error in the MP4 demuxer (vlc/modules/demux/mp4/mp4.c) when handling malformed files, which could be exploited by remote attackers to execute arbitrary code by tricking a user into opening a specially crafted MP4 file.