Description: Kevin Finisterre and LMH have reported a vulnerability in VLC media player, which can be exploited by malicious people to compromise a user's system.
The vulnerability is caused due to a format string error when handling "udp://" URIs and can be exploited via a specially crafted web site or an M3U file with a specially crafted udp:// URI containing format string specifiers as the file name.
Successful exploitation allows execution of arbitrary code.
The vulnerability is reported in version 0.8.6 and reportedly affects both Mac OS X and Windows versions. Other versions may be affected as well.
Do you have this product installed on your home computer? Scan using the free Personal Software Inspector. Check if a vulnerable version is installed on computers in your corporate network, scan using the Network Software Inspector.
Solution: Update to version 0.8.6a.
Provided and/or discovered by: Kevin Finisterre and LMH
Changelog: 2007-01-04: Updated "Solution Status" and added patch information from VideoLAN.
2007-01-18: Added CVE reference.
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.
Ideas, suggestions, and other feedback are most welcome.