Themes & Channels

Grab our RSS feed !

Stay informed !
Subscribe to our FREE newsletters...
 The Security Newsletter
 The Storage Newsletter

/images/public/sites/SecurityNewsletter.com/articles/illustrations/vulnerabilites_100.gif

Media players in trouble : QuickTime, VLC, AOL are vulnerables

Critical flaws have been exposed in popular media players Apple QuickTime, VLC and AOL's Radio Player. All could potentially compromise the host PC. Only AOL have submitted a patch yet.

Italian bug hunter Luigi Auriemma exposed two critical vulnerabilities within two of the most popular media players, Apple's QuickTime and VideoLan's free (and excellent !) VLC Media Player. Both could lead to running arbitrary code on PC by following  a malicious link.

Both vulnerabilities are related to the RTSP protocol used on the Internet to stream content in real-time. Each application is vulnerable in its latest version (QuickTime 7.3.1 and VLC 0.8.6d). No patch is available yet, and users are advised to not stream content from untrusted sites.

AOL got hit, too, through its AOL Radio tool. It was possible to execute arbitrary commands on the PC by exploiting a vulnerable component through an ActiveX control. This flaw got patched, though. 

More information :

 

News Options >

AddThis Social Bookmark Button

print this news Print this news

Check-out our sister site !
StorageNewsletter, the Daily Breaking News for the Worldwide IT Storage Industry

Into IAM ?

iam_small

The IAM 2008 Series

SecurityNewsletter interviews major Identity & Access Management players to give you the lead on what IAM will be in 2008.

Don't Miss Out !