VideoLan v2.0.5 possible vulnerability - execution of code

Microsoft Windows specific usage questions
Forum rules
Please post only Windows specific questions in this forum category. If you don't know where to post, please read the different forums' rules. Thanks.
Gopher
New Cone
New Cone
Posts: 2
Joined: 03 Mar 2013 23:23

VideoLan v2.0.5 possible vulnerability - execution of code

Postby Gopher » 03 Mar 2013 23:33

I have just attempted to play an AVI file with version 2.0.5 by double clicking the AVI file itself. The file did not play, but what ever the code was that executed it deleted the Opera directory and attempted to change FireFox, after which it didn't function properly anymore. The change to the system (WinXP Pro 32 SP3) also caused login issues. Immediately after this the system was restored from a previous backup and the problem fixed. I have a copy of the suspect AVI. I would like to know how to report this to the Devs so they can take a look at it. How do I do that?

TypX
Developer
Developer
Posts: 287
Joined: 21 Oct 2011 15:59

Re: VideoLan v2.0.5 possible vulnerability - execution of co

Postby TypX » 04 Mar 2013 11:33

First did you get your vlc from http://videolan.org/ or from a third party site? If the latter it may be a scam.
Else open a trac ticket on http://trac.videolan.org/vlc and upload the file on http://streams.videolan.org/upload

Gopher
New Cone
New Cone
Posts: 2
Joined: 03 Mar 2013 23:23

Re: VideoLan v2.0.5 possible vulnerability - execution of co

Postby Gopher » 04 Mar 2013 12:58

Thankyou for the reply TypX. Yes, my VLC was downloaded direct from the VLC website. I will open a ticket. I wanted to check with the group first as some organizations don't like tickets opened before discussion.

Jean-Baptiste Kempf
Site Administrator
Site Administrator
Posts: 37519
Joined: 22 Jul 2005 15:29
VLC version: 4.0.0-git
Operating System: Linux, Windows, Mac
Location: Cone, France
Contact:

Re: VideoLan v2.0.5 possible vulnerability - execution of co

Postby Jean-Baptiste Kempf » 10 Mar 2013 01:50

I wanted to check with the group first as some organizations don't like tickets opened before discussion.
This is a weird way...
Jean-Baptiste Kempf
http://www.jbkempf.com/ - http://www.jbkempf.com/blog/category/Videolan
VLC media player developer, VideoLAN President and Sites administrator
If you want an answer to your question, just be specific and precise. Don't use Private Messages.


Return to “VLC media player for Windows Troubleshooting”

Who is online

Users browsing this forum: No registered users and 18 guests