VLC media player RealText subtitle file ParseRealText buffer overflow

Added: 12/01/2008
CVE: CVE-2008-5036
BID: 32125
OSVDB: 49809

Background

VLC media player is a media player supporting various audio and video formats for multiple platforms.

Problem

A buffer overflow vulnerability in the ParseRealText function allows command execution when a user opens a media file which references a specially crafted RealText subtitle file.

Resolution

Upgrade to VLC media player 0.9.6 or higher.

References

http://www.videolan.org/security/sa0810.html

Limitations

Exploit works with VLC media player 0.9.4 and requires a user to download and save the MOV and RT files in the same directory, and then open the MOV file in VLC.

Platforms

Windows 2000
Windows XP

Back to exploit index