close

This ticket was migrated to our GitLab and can now be found here: #13389

Opened 6 years ago

Closed 6 years ago

Last modified 6 years ago

#13389 closed defect (notvlc)

VLC Player 2.1.5 DEP Access Violation Vulnerability

Reported by: Veysel Owned by:
Priority: high Milestone: Bugs paradize
Component: Unknown Version: master git
Severity: major Keywords:
Cc: vhatas@…, cehoyos, michaelni Difficulty: unknown
Platform(s): Windows desktop Work status: Not started

Description

Title : VLC Player 2.1.5 DEP Access Violation Vulnerability Discoverer: Veysel HATAS (vhatas@…) Web page : www.binarysniper.net Test: Windows XP SP3 Status: Not Fixed Severity : High

Discovered: 24 November 2014

Description : VLC Player contains a flaw that is triggered as user-supplied input is not properly sanitized when handling a specially crafted flv file. This may allow a context-dependent attacker to corrupt memory and cause a denial of service or potentially execute arbitrary code.

attachment 1: windbglog.txt attachment 2: poc.flv attachment 3: original.flv

Attachments (1)

windbglog.txt (14.5 KB) - added by Veysel 6 years ago.

Download all attachments as: .zip

Change History (10)

Changed 6 years ago by Veysel

Attachment: windbglog.txt added

comment:1 Changed 6 years ago by cehoyos

Cc: cehoyos added

comment:2 Changed 6 years ago by Jean-Baptiste Kempf

Was this tested against VLC 2.2.0?

And the files are not present.

comment:3 Changed 6 years ago by Veysel

You can find here : ​http://www.datafilehost.com/d/9565165f Pass: Qwertz

comment:4 Changed 6 years ago by Veysel

latest VLC - 2.1.5

No, this wasnt tested against VLC 2.2.0

comment:5 in reply to:  description Changed 6 years ago by Veysel

MITRE reserves CVE-ID (CVE-2014-9597) for the above vulnerability.

Last edited 6 years ago by Veysel (previous) (diff)

comment:6 Changed 6 years ago by Jean-Baptiste Kempf

Resolution: notvlc
Status: newclosed

So, this is NOT a VLC bug, but a libavcodec one.

Assigning a CVE to VLC is just wrong.

Moreover, the 2.2.0-rc2 binaries already fix the problem.

comment:7 Changed 6 years ago by Jean-Baptiste Kempf

Oh, btw, 2.1.5 Windows does not even crash on this sample.

comment:8 Changed 6 years ago by michaelni

Cc: michaelni added

comment:9 Changed 6 years ago by Veysel

For further technical details refer to

VLC Player 2.1.5 Write Access Violation (CVE-2014-9598) MITRE: ​http://cve.mitre.org/cgi-bin/cvename.cgi?name=2014-9598 NIST: ​https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-9598

VLC Player 2.1.5 DEP Access Violation (CVE-2014-9597) MITRE: ​http://cve.mitre.org/cgi-bin/cvename.cgi?name=2014-9597 NIST: ​https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-9597

Note: See TracTickets for help on using tickets.