Lucene search

K
saintSAINT CorporationSAINT:8F81E8D290541B0FB9EBEC7F2E682919
HistoryDec 01, 2008 - 12:00 a.m.

VLC media player RealText subtitle file ParseRealText buffer overflow

2008-12-0100:00:00
SAINT Corporation
download.saintcorporation.com
25

EPSS

0.97

Percentile

99.8%

Added: 12/01/2008
CVE: CVE-2008-5036
BID: 32125
OSVDB: 49809

Background

VLC media player is a media player supporting various audio and video formats for multiple platforms.

Problem

A buffer overflow vulnerability in the ParseRealText function allows command execution when a user opens a media file which references a specially crafted RealText subtitle file.

Resolution

Upgrade to VLC media player 0.9.6 or higher.

References

<http://www.videolan.org/security/sa0810.html&gt;

Limitations

Exploit works with VLC media player 0.9.4 and requires a user to download and save the MOV and RT files in the same directory, and then open the MOV file in VLC.

Platforms

Windows 2000
Windows XP