VLC media player RealText subtitle file ParseRealText buffer overflow
Added: 12/01/2008CVE: CVE-2008-5036
BID: 32125
OSVDB: 49809
Background
VLC media player is a media player supporting various audio and video formats for multiple platforms.Problem
A buffer overflow vulnerability in the ParseRealText function allows command execution when a user opens a media file which references a specially crafted RealText subtitle file.Resolution
Upgrade to VLC media player 0.9.6 or higher.References
http://www.videolan.org/security/sa0810.htmlLimitations
Exploit works with VLC media player 0.9.4 and requires a user to download and save the MOV and RT files in the same directory, and then open the MOV file in VLC.Platforms
Windows 2000Windows XP
Back to exploit index