HTTP: VideoLAN VLC Media Player XSPF Memory Corruption
This signature detects attempts to exploit a known memory corruption vulnerability in VideoLAN VLC Media Player. It is due to an integer-overflow error in the XSPF playlist file parser. An attacker can entice the target user to open a crafted XSPF file to exploit this. A successful attack can lead to arbitrary code execution within the context of the application.
Extended Description
VLC media player is prone to a heap-based memory-corruption vulnerability because the application fails to perform adequate boundary checks on user-supplied input. Attackers may leverage this issue to execute arbitrary code in the context of the application. Failed attacks will cause denial-of-service conditions. Versions prior to VLC Media Player 0.9.3 are vulnerable to this issue.
Affected Products
Videolan vlc_media_player
srx-branch-12.3
srx-19.3
srx-branch-19.3
vsrx3bsd-19.2
srx-branch-19.4
vsrx-19.4
mx-12.3
mx-19.4
vmx-19.4
mx-19.3
vsrx3bsd-19.4
srx-19.4
vsrx-12.3
vmx-19.3
vsrx-19.2
srx-12.3
Videolan
6.8