VLC: User-assisted execution of arbitrary code

Security Team  Contact Address

Updated April 23, 2008

1.  Gentoo Linux Security Advisory

Version Information

Advisory Reference GLSA 200804-25 / vlc
Release Date April 23, 2008
Latest Revision April 23, 2008: 01
Impact normal
Exploitable remote
Package Vulnerable versions Unaffected versions Architecture(s)
media-video/vlc < 0.8.6f >= 0.8.6f All supported architectures

Related bugreports: #214277, #214627

Synopsis

Multiple vulnerabilities were found in VLC, allowing for the execution of arbitrary code.

2.  Impact Information

Background

VLC is a cross-platform media player and streaming server.

Description

Multiple vulnerabilities were found in VLC:

Impact

A remote attacker could entice a user to open a specially crafted media file or stream, possibly resulting in the remote execution of arbitrary code.

3.  Resolution Information

Workaround

There is no known workaround at this time.

Resolution

All VLC users should upgrade to the latest version:

Code Listing 3.1: Resolution

# emerge --sync
# emerge --ask --oneshot --verbose ">=media-video/vlc-0.8.6f"

4.  References