VideoLAN.VLC.Media.Player.Remote.Format.String

description-logoDescription

This indicates an attempt to exploit a Format String vulnerability in VLC Media Player.
The vulnerability may allow a remote attacker to execute arbitrary code via an "M3U" file with a specially crafted "udp://" URL, with format string specifiers in the file.

affected-products-logoAffected Products

VideoLAN VLC versions 0.7.0 through 0.8.6

Impact logoImpact

System compromise: Remote code execution.

recomended-action-logoRecommended Actions

Upgrade to the latest version, available from the Web site.
http://www.videolan.org/vlc/

Telemetry logoTelemetry

Coverage

IPS (Regular DB)
IPS (Extended DB)

Version Updates

Date Version Detail
2023-08-01 25.612 Name:VideoLan.
VLC.
Media.
Player.
Remote.
Format.
String:VideoLAN.
VLC.
Media.
Player.
Remote.
Format.
String