Possible WriteAV Vulnerability
Version 2.1.3 OS: Windows 7 64
with a crafted .avs file VLC dies:
0:011> !load winext/msec.dll 0:011> !exploitable
!exploitable 1.6.0.0 *** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\Windows\syswow64\msvcrt.dll - *** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\Windows\syswow64\kernel32.dll - Exploitability Classification: EXPLOITABLE Exploitable - User Mode Write AV starting at libmpgatofixed32_plugin+0x00000000000016b4 (Hash=0xf1ffd179.0x98f1d37c)
I reproduce this crash in the Nightly builds with same results.. I have more information but is difficult paste that here..
Note:I will upload the .avs file with this ticket
regards,
John