This application requires Javascript for optimal performance.

VLC.HTTPD.Connection.Header.Format.String

Release Date

Dec 23, 2008

Severity

high

Impact

System Compromise: Remote attackers can gain control of vulnerable systems.

Description

This indicates an attack attempt against a format-string vulnerability in VideoLAN VLC HTTPD.

The vulnerability is caused by an error when the vulnerable software handles a malicious "Connection" parameter. It allows a remote attacker to execute arbitrary code via sending a crafted web request.

Affected Products

VideoLAN VLC media player 0.8.6d
VideoLAN VLC media player 0.8.6c
VideoLAN VLC media player 0.8.6b
VideoLAN VLC media player 0.8.6a

Recommended Actions

Upgrade to the latest version, available from the vendor's web site:
http://www.videolan.org/

Coverage

IPS
VCM

Common Vulnerabilities and Exposures (CVE)

CVE-2007-6682

Reference/s

http://milw0rm.com/exploits/5519
http://www.securityfocus.com/bid/27015 (BugTraq)

Reference: VID-16682