«
Expand/Collapse
88 items tagged "vlc"
Related tags:
memory corruption [+],
buffer overflow [+],
uri [+],
txt [+],
stack buffer [+],
remote buffer overflow [+],
videolan [+],
validation error [+],
integer overflow [+],
crash proof [+],
player 1 [+],
denial of service [+],
buffer overflow vulnerabilities [+],
vlc media player [+],
xspf [+],
mms [+],
exploits [+],
denial of service exploit [+],
based buffer overflow [+],
ape file [+],
amv [+],
media [+],
player [+],
subtitle files [+],
subtitle [+],
realtext [+],
player v1 [+],
parser [+],
overflow [+],
module [+],
mkv [+],
media player version [+],
m stack [+],
input validation [+],
flv file [+],
dsa [+],
dangling pointer [+],
buffer overflow exploit [+],
amr file [+],
videolan sa [+],
uri handling [+],
service vulnerability [+],
security vulnerabilities [+],
quot [+],
pointer [+],
player versions [+],
package [+],
mail [+],
linux security [+],
gmail [+],
feature [+],
error [+],
division [+],
debian linux [+],
data validation [+],
code execution [+],
bt4 [+],
arbitrary code execution [+],
and [+],
Requests [+],
BackTrack [+],
zero [+],
vulnerabilities [+],
vlc player [+],
today [+],
synaptic [+],
stream [+],
stack overflow [+],
service [+],
server error [+],
security [+],
safer use [+],
problem [+],
nsv files [+],
nsv [+],
mplayer [+],
mp4 files [+],
media players [+],
libtaglib [+],
heap [+],
golden eye [+],
golden [+],
eye [+],
eac [+],
dos [+],
dll [+],
denial [+],
deb [+],
data transport [+],
dangling [+],
cannot [+],
beta [+],
Newbie [+],
General [+],
Discussion [+],
Area [+],
poc [+],
buffer overflow vulnerability [+],
vulnerability [+]
-
-
15:45
»
Packet Storm Security Exploits
This Metasploit module exploits a buffer overflow in VLC media player VLC media player prior to 2.0.0. The vulnerability is due to a dangerous use of sprintf which can result in a stack buffer overflow when handling a malicious MMS URI. This Metasploit module uses the browser as attack vector. A specially crafted MMS URI is used to trigger the overflow and get flow control through SEH overwrite. Control is transferred to code located in the heap through a standard heap spray. The module only targets IE6 and IE7 because no DEP/ASLR bypass has been provided.
-
15:45
»
Packet Storm Security Recent Files
This Metasploit module exploits a buffer overflow in VLC media player VLC media player prior to 2.0.0. The vulnerability is due to a dangerous use of sprintf which can result in a stack buffer overflow when handling a malicious MMS URI. This Metasploit module uses the browser as attack vector. A specially crafted MMS URI is used to trigger the overflow and get flow control through SEH overwrite. Control is transferred to code located in the heap through a standard heap spray. The module only targets IE6 and IE7 because no DEP/ASLR bypass has been provided.
-
15:45
»
Packet Storm Security Misc. Files
This Metasploit module exploits a buffer overflow in VLC media player VLC media player prior to 2.0.0. The vulnerability is due to a dangerous use of sprintf which can result in a stack buffer overflow when handling a malicious MMS URI. This Metasploit module uses the browser as attack vector. A specially crafted MMS URI is used to trigger the overflow and get flow control through SEH overwrite. Control is transferred to code located in the heap through a standard heap spray. The module only targets IE6 and IE7 because no DEP/ASLR bypass has been provided.
-
-
18:53
»
Packet Storm Security Exploits
This Metasploit module exploits a stack buffer overflow vulnerability in VideoLAN VLC versions prior to 0.9.6. The vulnerability exists in the parsing of RealText subtitle files. In order to exploit this, this module will generate two files: The .mp4 file is used to trick your victim into running. The .rt file is the actual malicious file that triggers the vulnerability, which should be placed under the same directory as the .mp4 file.
-
18:53
»
Packet Storm Security Recent Files
This Metasploit module exploits a stack buffer overflow vulnerability in VideoLAN VLC versions prior to 0.9.6. The vulnerability exists in the parsing of RealText subtitle files. In order to exploit this, this module will generate two files: The .mp4 file is used to trick your victim into running. The .rt file is the actual malicious file that triggers the vulnerability, which should be placed under the same directory as the .mp4 file.
-
18:53
»
Packet Storm Security Misc. Files
This Metasploit module exploits a stack buffer overflow vulnerability in VideoLAN VLC versions prior to 0.9.6. The vulnerability exists in the parsing of RealText subtitle files. In order to exploit this, this module will generate two files: The .mp4 file is used to trick your victim into running. The .rt file is the actual malicious file that triggers the vulnerability, which should be placed under the same directory as the .mp4 file.
-
-
17:36
»
Packet Storm Security Exploits
VLC Media Player suffers from an XSPF local file integer overflow in the XSPF playlist parser. Versions 1.1.9 down to 0.8.5 are affected.
-
-
20:24
»
SecuriTeam
VLC Media Player contains two Buffer Overflow vulnerabilities.
-
Make your website safer. Use external penetration testing service. First report ready in one hour!
-
-
21:28
»
Packet Storm Security Exploits
This Metasploit module exploits an input validation error in libmod_plugin as included with VideoLAN VLC 1.1.8. All versions prior to version 1.1.9 are affected. By creating a malicious S3M file, a remote attacker could execute arbitrary code. Although other products that bundle libmodplug may be vulnerable, this module was only tested against VLC. NOTE: As of July 1st, 2010, VLC now calls SetProcessDEPPoly to permanently enable NX support on machines that support it. As such, this module is capable of bypassing DEP, but not ASLR.
-
21:28
»
Packet Storm Security Recent Files
This Metasploit module exploits an input validation error in libmod_plugin as included with VideoLAN VLC 1.1.8. All versions prior to version 1.1.9 are affected. By creating a malicious S3M file, a remote attacker could execute arbitrary code. Although other products that bundle libmodplug may be vulnerable, this module was only tested against VLC. NOTE: As of July 1st, 2010, VLC now calls SetProcessDEPPoly to permanently enable NX support on machines that support it. As such, this module is capable of bypassing DEP, but not ASLR.
-
21:28
»
Packet Storm Security Misc. Files
This Metasploit module exploits an input validation error in libmod_plugin as included with VideoLAN VLC 1.1.8. All versions prior to version 1.1.9 are affected. By creating a malicious S3M file, a remote attacker could execute arbitrary code. Although other products that bundle libmodplug may be vulnerable, this module was only tested against VLC. NOTE: As of July 1st, 2010, VLC now calls SetProcessDEPPoly to permanently enable NX support on machines that support it. As such, this module is capable of bypassing DEP, but not ASLR.
-
11:37
»
Packet Storm Security Exploits
This Metasploit module exploits VLC media player when handling a .AMV file. By flipping the 0x41st byte in the file format (video width/height), VLC crashes due to an invalid pointer, which allows remote attackers to gain arbitrary code execution. The vulnerable packages include: VLC 1.1.4 VLC 1.1.5 VLC 1.1.6 VLC 1.1.7.
-
11:37
»
Packet Storm Security Misc. Files
This Metasploit module exploits VLC media player when handling a .AMV file. By flipping the 0x41st byte in the file format (video width/height), VLC crashes due to an invalid pointer, which allows remote attackers to gain arbitrary code execution. The vulnerable packages include: VLC 1.1.4 VLC 1.1.5 VLC 1.1.6 VLC 1.1.7.
-
-
20:00
»
Packet Storm Security Recent Files
Debian Linux Security Advisory 2043-1 - tixxDZ (DZCORE labs) discovered a vulnerability in vlc, the multimedia player and streamer. Missing data validation in vlc's real data transport (RDT) implementation enable an integer underflow and consequently an unbounded buffer operation. A maliciously crafted stream could thus enable an attacker to execute arbitrary code.
-
20:00
»
Packet Storm Security Advisories
Debian Linux Security Advisory 2043-1 - tixxDZ (DZCORE labs) discovered a vulnerability in vlc, the multimedia player and streamer. Missing data validation in vlc's real data transport (RDT) implementation enable an integer underflow and consequently an unbounded buffer operation. A maliciously crafted stream could thus enable an attacker to execute arbitrary code.
-
-
8:44
»
remote-exploit & backtrack
Hello experts, I'm using BT4 in my usb for portable purpose.
On the run,, i would like to view movies.
So, i encouraged to install VLC
apt-get vlc
But, i find error, while unpacking deb.
Could you tell me,
1.after typing the command "apt-get vlc"
were the downloaded items get stored.
2.How to overcome the error.
mail me if you have more details share.
with regards,
Nirmal jose.
nirmaljose1309@gmail.com:rolleyes::rolleyes:
-
8:44
»
remote-exploit & backtrack
Hello experts, I'm using BT4 in my usb for portable purpose.
On the run,, i would like to view movies.
So, i encouraged to install VLC
apt-get vlc
But, i find error, while unpacking deb.
Could you tell me,
1.after typing the command "apt-get vlc"
were the downloaded items get stored.
2.How to overcome the error.
mail me if you have more details share.
with regards,
Nirmal jose.
nirmaljose1309@gmail.com:rolleyes::rolleyes:
-
-
3:56
»
remote-exploit & backtrack
Today i try install vlc (sudo apt-get install vlc).
But it did not install
Quote:
\/vlc_0.9.4-1ubuntu3.1_i386.deb[/url] 404 Not Found
E: Unable to fetch some archives, maybe run apt-get update or try with --fix-missing?
|
server error
this output after 50% download. What is the problem?
-
-
5:22
»
remote-exploit & backtrack
Is there any good media players for bt 4 beta.
i installed vlc via synaptic. but it says it cannot be run as root.
also is there any way of creating a useraccount.