VLC Media Player RTSP Remote Code Execution Vulnerability
Publish Date: 21 juillet 2015
Gravité: : Élevé
Date du conseil: 21 juillet 2015
Description
The parseRTSPRequestString function VideoLAN VLC Media Player, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a (1) space or (2) tab character at the beginning of an RTSP message, which triggers an integer underflow, infinite loop, and buffer overflow.
Information Exposure Rating:
Apply associated Trend Micro DPI Rules.
Solutions
Trend Micro Deep Security DPI Rule Number: 1005863