HTTP: VLC Media Player libdirectx_plugin.dll Plugin Remote Code Execution

This signature detects attempts to use unsafe ActiveX controls in the VLC Media Player libdirectx_plugin.dll Plugin. An attacker can create a malicious Web site containing Web pages with dangerous ActiveX controls, which if accessed by a victim, allows the attacker to gain control of the victim's client browser.

Extended Description

VLC media player is prone to multiple buffer-overflow vulnerabilities. Attackers can exploit these issues to execute arbitrary code in the context of the affected application or crash the application, denying service to legitimate users. Versions prior to VLC media player 1.1.8 are vulnerable.

Affected Products

Debian linux

References

BugTraq: 47012

CVE: CVE-2010-3275

Short Name
HTTP:STC:ACTIVEX:VLC-PLY-RCE
Severity
Minor
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
CVE-2010-3275 Code Execution Media Player Plugin Remote VLC bid:47012 libdirectx_plugin.dll
Release Date
11/09/2011
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3336
False Positive
Unknown
Vendors

Videolan

Debian

CVSS Score

9.3

Found a potential security threat?