27878Third-party advisory
http://secunia.com/advisories/27878 CVE-2007-6262
VideoLAN VLC Media Player 0.86 < 0.86d - ActiveX Remote Bad Pointer Initialization
Record summary
CVE-2007-6262 has a selected CVSS score of 6.8; EIP currently links 1 catalogued exploit.
Description
A certain ActiveX control in axvlc.dll in VideoLAN VLC 0.8.6 before 0.8.6d allows remote attackers to execute arbitrary code via crafted arguments to the (1) addTarget, (2) getVariable, or (3) setVariable function, resulting from a "bad initialized pointer," aka a "recursive plugin release vulnerability."
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBVideoLAN VLC Media Player 0.86 < 0.86d - ActiveX Remote Bad Pointer InitializationExploitDB exploitby Ricardo NarvajaNot analyzed1 file
References
103420Third-party advisory
http://securityreason.com/securityalert/3420 coresecurity.com
http://www.coresecurity.com/?action=item&id=2035 20071204 CORE-2007-1004: VLC Activex Bad Pointer Initialization Vulnerabilitymailing list
http://www.securityfocus.com/archive/1/484563/100/0/threaded 26675vdb entry
http://www.securityfocus.com/bid/26675 videolan.orgConfirmation
http://www.videolan.org/sa0703.html ADV-2007-4061vdb entry
http://www.vupen.com/english/advisories/2007/4061 vlcmediaplayer-activex-memory-overwrite(38816)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/38816 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2007-6262 oval:org.mitre.oval:def:14280vdb entrysignature
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14280