TorrentFreak

The place where breaking news, BitTorrent and copyright collide

VLC Player Vulnerable to Remote Hijack

VLC Player, one of the best and most widely used media players has found to be vulnerable to a remote hijack. The reported vulnerability makes it possible for a malicious user to run arbitrary code, potentially taking remote control of the host machine.

vlc media playerVLC is a popular media player among BitTorrent users. Not just for the fact that it is free, also because it includes a huge number of the video codecs, so it can play virtually every video file available.

Unfortunately, the latest versions of VLC have a security flaw according to a report from Luigi Auriemma. The vulnerability can be exploited to compromise a user’s system, as it leaves it wide open for a malicious user to run arbitrary code.

The problem occurs when a someone loads a subtitle file, which causes a buffer overflow that can be exploited. The security flaw is platform independent, which means it affects Windows, Mac and Linux users.

Initially it was reported that the flaws in version 0.8.6d were fixed in the latest release, but this turns out not to be the case. Auriemma writes: “The old buffer-overflow in the subtitles handled by VLC has not been fully patched in version 0.8.6e.”

“The funny thing is that my old proof-of-concept was built just to test this specific buffer-overflow and in fact it works on the new VLC version too without modifications,” he adds.

For now, the only solutions are not to run any subtitle files, or to grab one of the nightly builds. The downside is, however, that these might not be as stable as the regular releases.

Related Posts

Previous Post | Next Post

  • Mediaget
  • Download Torrents with BTguard

NewsBits

The latest news from around the web, not covered on the frontpage

  • Polish Protests Put ACTA ‘On Hold’

    Last week the European Union has officially signed the controversial “anti-piracy” trade agreement ACTA. This brings...

  • Ex.ua Makes a Miraculous Comeback

    A few days ago we reported that the Ukrainian authorities shut down the popular file-hosting site...

  • uTorrent Gets a Browser Control Add-On

    The uTorrent team just released browser add-ons for Firefox, Chome and IE. uTorrent Control allows users...

  • Rogers Finally Stops BitTorrent Throttling

    Rogers, one of Canada’s largest Internet providers, has been slowing down BitTorrent traffic since 2005. Recent...

  • Piracy Is The New Radio, Says Neil Young

    Neil Young has been making music for nearly 50 years, so we have to assume that...

MostDiscussed

Below are TorrentFreak's most discussed articles of the past month. Join the discussion if you like.

CopyQuote

Left Quote

“The Pirate Bay has been one of the most important movements in Sweden for freedom of speech, working against corruption and censorship.

Peter Sunde Left Quote

RecommendedArticles

A selection of some TorrentFreak's classics dug up from our archives.