Just an FYI, found this at yahoo News:
A flaw in the widely-used open-source VLC media player could allow an attacker to execute harmful code on a PC.
ADVERTISEMENT
The problem stems from a buffer overflow that can occur when the player processes subtitle files used for movies, according to a security advisory.
The vulnerability existed before VLC was upgraded to version 0.8.6e in late February, but the bug appears to have escaped the last round of patches, wrote Luigi Auriemma in a note.
"The funny thing is that my old proof-of-concept was built just to test this specific buffer overflow, and in fact it works on the new VLC version too without modifications," Auriemma wrote.
Video files can contain a link to a separate subtitle file, which VLC automatically loads when it plays the video. An attacker could use the buffer overflow flaw in VLC to execute malicious code contained in a subtitle file, and thus tamper with a PC. The flaw affects VLC players running on Windows, Mac, BSD and possibly more operating systems, Auriemma wrote.
The VLC media player is part of the VideoLAN project. The player is free, and it is released under the GNU General Public License. VLC can also be used as a streaming media server for a variety of platforms.
+ Reply to Thread
Results 1 to 5 of 5
-
-
Originally Posted by redwudz
-
I dont use subtitles ... and I have no desire for any video with subtitles
-
The quick fix for VLC would be to simply disallow the automatic loading of subtitles (I had no idea this was even possible) and force to you manually specify the subtitle file to use (what I do), which you presumably would at least look at prior to opening to be sure it's really subtitles and not malicious code.
Similar Threads
-
Cannot play avi file with vlc player/divx player or GOM Media Player (GAVC)
By texasdontholdem in forum Software PlayingReplies: 11Last Post: 5th Aug 2016, 07:28 -
display size between windows media player and VLC player
By kool_k in forum Software PlayingReplies: 4Last Post: 6th Aug 2011, 15:18 -
Better media player than VLC?
By meneedit in forum Software PlayingReplies: 5Last Post: 16th Nov 2010, 07:32 -
vlc media player
By natty in forum Newbie / General discussionsReplies: 5Last Post: 30th Aug 2010, 13:10 -
VLC Media Player
By Flying Doctor in forum Video ConversionReplies: 4Last Post: 26th Jun 2007, 09:38