Memory Corruption Flaws Found In VLC Media Player

Users of the popular open source media player VLC could be susceptible to two memory corruption flaws affecting some versions of the software running on Windows XP.

Turkish researcher Veysel Hatas discovered the vulnerabilities in VLC 2.1.5 in November and reported them to the VLC project’s developers VideoLAN on 26 December before publishing the findings on the 9 January after they weren’t fixed.

Hatas said the severity of both flaws was “high” and were posted on Full Disclosure last week.

VLC vulnerabilities

“VLC Media Player contains a flaw that is triggered as user-supplied input is not properly sanitized when handling a specially crafted FLV file,” said Hatas of the first vulnerability. “This may allow a context-dependent attacker to corrupt memory and potentially execute arbitrary code.”

“VLC Media Player contains a flaw that is triggered as user-supplied input is not properly sanitized when handling a specially crafted M2V file,” Hatas described the second bug. “This may allow a context-dependent attacker to corrupt memory and potentially execute arbitrary code.”

VideoLAN told TechWeekEurope that the bugs described are NOT VLC vulnerabilities and have already been fixed upstream and that most Linux distributions have already fixed them. It added that VLC 2.2.0-rc2 already fixes the issue for Windows and OSX and claimed the issue was not exploitable.

“The reporter was notified, and did not care,” said the organisation.

Are you a security pro? Try our quiz!

Steve McCaskill

Steve McCaskill is editor of TechWeekEurope and ChannelBiz. He joined as a reporter in 2011 and covers all areas of IT, with a particular interest in telecommunications, mobile and networking, along with sports technology.

Recent Posts

Amazon Workers In North Carolina Reject Unionisation

Workers at Amazon warehouse near Raleigh vote against joining union, as company continues to challenge…

11 hours ago

China President Xi Meets With Top Tech Leaders

High-profile meeting with tech leaders seen as signal China is boosting tech sector after years…

12 hours ago

South Korea To Buy 10,000 GPUs For National AI Hub

South Korea hopes to gain leg up in international AI race with infusion of private…

12 hours ago

BYD, Geely, Great Wall Add DeepSeek AI To EVs

Chinese electric vehicle giants rush to incorporate DeepSeek AI tech to cars after it creates…

13 hours ago

South Korea Suspends DeepSeek From App Stores

South Korean data authority suspends Chinese AI start-up DeepSeek from Apple, Google app stores while…

13 hours ago

Google Puts ‘Profits Over Privacy’ With Tracking Change

Privacy advocates criticise Google over decision to allow companies to track users via digital fingerprints,…

14 hours ago