<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>TorrentFreak &#187; remote exploit</title>
	<atom:link href="http://torrentfreak.com/tag/remote-exploit/feed/" rel="self" type="application/rss+xml" />
	<link>http://torrentfreak.com</link>
	<description>Torrent News, Torrent Sites and the latest Scoops</description>
	<lastBuildDate>Fri, 20 Nov 2009 23:34:24 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.3</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>VLC Player Vulnerable to Remote Hijack</title>
		<link>http://torrentfreak.com/vlc-player-vulnerable-remote-hijack-080318/</link>
		<comments>http://torrentfreak.com/vlc-player-vulnerable-remote-hijack-080318/#comments</comments>
		<pubDate>Tue, 18 Mar 2008 21:29:23 +0000</pubDate>
		<dc:creator>Ernesto</dc:creator>
				<category><![CDATA[DRM and Other Evil]]></category>
		<category><![CDATA[Hot Off The Press]]></category>
		<category><![CDATA[remote exploit]]></category>
		<category><![CDATA[vlc]]></category>
		<category><![CDATA[vulnerability]]></category>

		<guid isPermaLink="false">http://torrentfreak.com/vlc-player-vulnerable-remote-hijack-080318/</guid>
		<description><![CDATA[VLC Player, one of the best and most widely used media players has found to be vulnerable to a remote hijack. The reported vulnerability makes it possible for a malicious user to run arbitrary code, potentially taking remote control of the host machine.]]></description>
			<content:encoded><![CDATA[<p><img src="http://torrentfreak.com//images/vlc.jpg" align="right"  alt="vlc media player" /><a href="http://www.videolan.org/vlc/">VLC</a> is a popular media player among BitTorrent users. Not just for the fact that it is free, also because it includes a huge number of the video codecs, so it can play virtually every video file available. </p>
<p>Unfortunately, the latest versions of VLC have a security flaw according to a <a href="http://secunia.com/advisories/28233/">report</a> from Luigi Auriemma. The vulnerability can be exploited to compromise a user&#8217;s system, as it leaves it wide open for a malicious user to run arbitrary code.</p>
<p>The problem occurs when a someone loads a subtitle file, which causes a buffer overflow that can be exploited. The security flaw is platform independent, which means it affects Windows, Mac and Linux users.</p>
<p>Initially it was reported that the flaws in version 0.8.6d were fixed in the latest release, but this turns out not to be the case. Auriemma <a href="http://securityvulns.com/Tdocument429.html">writes</a>: &#8220;The old buffer-overflow in the subtitles handled by VLC has not been fully patched in version 0.8.6e.&#8221;</p>
<p>&#8220;The funny thing is that my old proof-of-concept was built just to test this specific buffer-overflow and in fact it works on the new VLC version too without modifications,&#8221; he adds.</p>
<p>For now, the only solutions are not to run any subtitle files, or to grab one of the <a href="http://nightlies.videolan.org/">nightly builds</a>. The downside is, however, that these might not be as stable as the regular releases.</p>
<p>Article from: <a href="http://torrentfreak.com">TorrentFreak</a>, check out our new blog at <a href="http://freakbits.com">FreakBits</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://torrentfreak.com/vlc-player-vulnerable-remote-hijack-080318/feed/</wfw:commentRss>
		<slash:comments>122</slash:comments>
		</item>
	</channel>
</rss>
