NASLDB: VLC Media Player < 1.0.1 real_get_rdt_chunk() Function Overflow
General
ID: 40466
Name: VLC Media Player < 1.0.1 real_get_rdt_chunk() Function Overflow
Summary: Checks version of VLC
Credits: –
Classification
Risk: –
CVSS: –
CVSS Base Vector: CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C
CVSS Temporal Vector: CVSS2#E:U/RL:OF/RC:C
Port: –
Family: Windows
Type: Local
Description
The version of VLC media player installed on the remote host is
earlier than 1.0.1. Such versions contain an integer underflow
involving the integer ‘size’ in the ‘real_get_rdt_chunk_header()’
function that can be triggered when reading Real Data Transport (RDT)
chunk headers. This ‘size’ variable is used before the underflow to
allocate storage on the heap and then after it to read an excessive
amount of data from the network via the ‘rtsp_read_data()’ function,
resulting in a buffer overflow. If an attacker can trick a user into
opening a specially crafted RTSP stream with the affected application,
he may be able to execute arbitrary code subject to the user’s
privileges.
Exploiting
Exploit Available: False
Exploitability Ease: No known exploits are available
Sources
CVE: –
OSVDB: –
Bugtraq: –
scipID: –
Timeline
Vulnerability Disclosure: 2009/07/27
Patch Release: 2009/07/28
Plugin Release: 2009/08/01
Plugin
Version: 1.6
Filename: vlc_1_0_1.nasl
Filesize: 3281 bytes
MD5 Hash: 38aa6d004d47f0461846215ec4592283
Identification: SMB/VLC/Version
Require Keys: SMB/VLC/Version
Dependencies: "vlc_installed.nasl"
Copyright: This script is Copyright© 2009-2011 Tenable Network Security, Inc.
- Latest Plugins
- USN-1611-1 : thunderbird vulnerabilities
- USN-1610-1 : linux vulnerability
- USN-1609-1 : linux-ti-omap4 vulnerability
- SuSE 10 Security Update : PostgreSQL
- RHSA-2012-1364: bind97
- RHSA-2012-1363: bind
- RHSA-2012-1362: thunderbird
- RHSA-2012-1361: xulrunner
- Mandriva Linux Security Advisory : graphicsmagick
- FreeBSD : phpMyAdmin — Multiple XSS due to unescaped HTML output in Trigger, Procedure and Event pages and Fetching the version information from a non-SSL site is vulnerable to a MITM attack













