The MP4 demuxer (mp4.c) for VLC media player 0.8.6d and earlier, as used in Miro Player 1.1 and earlier, allows remote attackers to overwrite arbitrary memory and execute arbitrary code via a malformed MP4 file.
Weaknesses in this category are related to improper management of system resources.
Link | Tags |
---|---|
http://secunia.com/advisories/29122 | third party advisory vendor advisory |
http://secunia.com/advisories/29284 | third party advisory vendor advisory |
http://www.debian.org/security/2008/dsa-1543 | vendor advisory |
http://secunia.com/advisories/29153 | third party advisory vendor advisory |
http://www.videolan.org/security/sa0802.html | patch |
http://www.securityfocus.com/bid/28007 | vdb entry |
http://www.securitytracker.com/id?1019510 | vdb entry |
http://lists.grok.org.uk/pipermail/full-disclosure/2008-February/060481.html | mailing list |
http://www.securityfocus.com/archive/1/488841/100/0/threaded | mailing list |
http://secunia.com/advisories/29766 | third party advisory vendor advisory |
http://www.vupen.com/english/advisories/2008/0682 | vdb entry vendor advisory |
http://www.coresecurity.com/?action=item&id=2147 | |
http://www.gentoo.org/security/en/glsa/glsa-200803-13.xml | vendor advisory |