HomeSecurityVLC media player: 2 critical vulnerabilities identified. Update immediately!

VLC media player: 2 critical vulnerabilities identified. Update immediately!

The VLC media player has two high-risk security flaws in software versions 3.0.6 and earlier that allow hackers to upload specially crafted video files to the vulnerable system to execute arbitrary code.

For those who don't know, VLC media player is one of the best and most popular media players with over 3 billion downloads.

It is a free and open source platform that can be used on Windows, MacOS, Linux, as well as on Android and iOS mobile platforms. Whatever the format, VLC Media Player can play almost any type of audio and video you want.

VLC

The vulnerability is named CVE-2019-12874 and is located in the “zlib_decompress_extra() (demux/mkv/utils.cpp)” function of VideoLAN VLC Player. It can be triggered when a faulty mkv file type is detected in the Matroska demuxer.

A second high-risk flaw called CVE-2019-5439 was identified and, in essence, is a buffer overflow vulnerability located in ReadFrame (demux / avi / avi.c).

It allows a remote user to create some specially crafted avi or mkv files which, when loaded by the target user, will trigger a buffer overflow.

Successful execution of an infected file on the system could cause either a VLC crash or arbitrary code with the privileges of the target user.

VLC media player: 2 critical vulnerabilities identified. Update immediately!

A potential attacker could exploit these vulnerabilities by tricking the user into opening a specially crafted malicious MKV or AVI video file.

VLC users are strongly advised to upgrade their media player software to VLC 3.0.7 version or later to prevent hackers from exploiting this vulnerability on their systems.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS