There are two memory corruption vulnerabilities in some versions of the VLC open-source media player that can allow an attacker to run arbitrary code on vulnerable machines. . Neither one of the vulnerabilities has been fixed by VideoLAN, the organization that maintains VLC. Security researcher Veysel Hatas reported the vulnerabilities to VideoLAN in December and published the advisories on Full Disclosure on Friday. One of the bugs is a DEP access violation vulnerability and the other is is a write access flaw. The link for this article located at ThreatPost is no longer available. . Two memory management vulnerabilities in VLC may allow attackers to execute unauthorized commands on unpatched systems. Stay informed about effective countermeasures. Memory Flaw, VLC Media Player, Code Execution Risk, Security Advisory. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.