Parsing a WEBM file baldy crashes VLC 1.1.10 on Windows
Opening VLC 1.1.10
Microsoft (R) Windows Debugger Version 6.12.0002.633 X86 Copyright (c) Microsoft Corporation. All rights reserved.
[...] ModLoad: 043d0000 044e4000 C:\Program Files\VideoLAN\VLC\plugins\libtaglib_plugin.dll (bc8.a8): Unknown exception - code c0000096 (first chance) (bc8.a8): Unknown exception - code c0000096 (!!! second chance !!!) eax=9335bbbe ebx=00e37272 ecx=474e5543 edx=432b2b00 esi=0235fbf0 edi=00000001 eip=0235fa6d esp=0235fbb4 ebp=0235fc10 iopl=0 nv up ei ng nz na pe nc cs=001b ss=0023 ds=0023 es=0023 fs=0038 gs=0000 efl=00000286 0235fa6d 0000 add byte ptr [eax],al ds:0023:9335bbbe=?? *** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\Program Files\VideoLAN\VLC\plugins\libmkv_plugin.dll - 0:008> !MSEC.exploitable *** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\Program Files\VideoLAN\VLC\libvlccore.dll - Exploitability Classification: EXPLOITABLE Recommended Bug Title: Exploitable - Exception generated by code running in the Stack starting at Unknown Symbol @ 0x000000000235fa6d called from libmkv_plugin!vlc_entry__1_1_0g+0x000000000005aef1 (Hash=0x0b607c5f.0x523a3d37)
Code execution from the stack is considered exploitable