| Title |
VideoLAN VLC Multiple Remote Code Execution Vulnerabilities |
| Published |
2007-12-24-12:00AM |
| Updated |
2008-03-07-11:11PM |
| Class |
Unknown |
| CVE |
CVE-2007-6681 E-2007-6682 |
| Remote |
Yes |
| Local |
No |
| Credit |
Michal Luczaj is credited with the discovery of the buffer-overflow vulnerabilities. Luigi Auriemma discovered the format-string vulnerability. |
| Vulnerable |
VideoLAN VLC media player 0.8.6 d VideoLAN VLC media player 0.8.6 VideoLAN VLC media player 0.8.6 VideoLAN VLC media player 0.8.6b VideoLAN VLC media player 0.8.6a Gentoo Linux
|
| Not Vulnerable |
|
| Code |
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.The following proof-of-concept code is available: /data/vulnerabilities/exploits/vlcboffs.zip |
| TXT |
 |