VLC AMV Dangling Pointer Vulnerability

0
95

This Metasploit module exploits VLC media player when handling a .AMV file. By flipping the 0x41st byte in the file format (video width/height), VLC crashes due to an invalid pointer, which allows remote attackers to gain arbitrary code execution. The vulnerable packages include: VLC 1.1.4 VLC 1.1.5 VLC 1.1.6 VLC 1.1.7.

Source: VLC AMV Dangling Pointer Vulnerability