Skip to content

VLC crashes with crafted subtitle file, allowing attackers to inject malicious code

The exploit for it was released 3 days ago on milw0rm [0] and heise-security [1] has added and article about it.

I'm using VLC 0.8.6c on Linux 2.6.24.3 and it crashes with crafted subtitle file produced by exploit. I tried 0.8.6e and it crashes too.

[0] http://www.milw0rm.com/exploits/5250

[1] http://www.heise-online.co.uk/security/VLC-media-player-trips-up-on-subtitles--/news/110328

To upload designs, you'll need to enable LFS and have an admin enable hashed storage. More information