VLC Media Player contains a format string vulnerability that may allow a malicious user to excecute arbitrary code. The issue is triggered when a specially crafted .ogm (Theora) file is processed by the player. It is possible that the flaw may allow code excecution and memory corruption resulting in a loss of integrity.
Classification
Location:
Remote/Network Access Required
Attack Type:
Input Manipulation
Impact:
Loss of Integrity
Exploit:
Exploit Unknown
Disclosure:
OSVDB Verified
Solution
Upgrade to version 0.8.6c or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.
CVE-2007-3316 Publish Date: 6/21/2007 Multiple format string vulnerabilities in plugins in VideoLAN VLC Media Player before 0.8.6c allow remote attackers to cause a denial of service (crash