VideoLAN VLC media player »º³åÇøÃýÎó·ì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2019-07-22

·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-13615£¬Î£ÏÕ¼¶±ð£ºÑϳÁ£¬CVSS·ÖÖµ£º9.8


Ó°Ïì°æ±¾


ÊÜÓ°ÏìµÄ°æ±¾


VideoLAN VLC media player 3.0.7.1


·ì϶¸ÅÊö


VideoLAN VLC media playerÊÇ·¨¹úVideoLAN×éÖ¯µÄÒ»¿îÃâ·Ñ¡¢¿ªÔ´µÄ¿çƽ̨¶àýÌå²¥·ÅÆ÷£¨Ò²ÊÇÒ»¸ö¶àýÌå¿ò¼Ü£©  ¡£¸Ã²úÆ·Ö§³Ö²¥·Å¶àÖÖ½éÖÊ£¨Îļþ¡¢¹âÅ̵ȣ©¡¢¶àÖÖÒôÊÓÆµÌåʽ£¨WMV,MP3µÈ£©µÈ  ¡£


VideoLAN VLC media player 3.0.7.1°æ±¾ÖеÄmodules/demux/mkv/demux.cppÎļþµÄmkv::demux_sys_t::FreeUnused()´æÔÚ»º³åÇøÃýÎó·ì϶  ¡£¸Ã·ì϶ԴÓÚÍøÂçϵͳ»ò²úÆ·ÔÚÄÚ´æÉÏÖ´ÐвÙ×÷ʱ£¬Î´ÕýÈ·ÑéÖ¤Êý¾ÝÌìǵ£¬µ¼ÖÂÏò¹ØÁªµÄÆäËûÄÚ´æµØÎ»ÉÏÖ´ÐÐÁËÃýÎóµÄ¶Áд²Ù×÷  ¡£¹¥»÷Õß¿ÉÀûÓø÷ì϶µ¼Ö»º³åÇøÒç³ö»ò¶ÑÒç³öµÈ  ¡£ 


·ì϶ÑéÖ¤


ÔÝÎÞPOC/EXP  ¡£ 


½¨¸´½¨Òé


Ŀǰ³§ÉÌÔÝδ°ä²¼½¨¸´´ëÊ©½â¾ö´Ë°²È«ÎÊÌ⣬½¨ÒéʹÓôËÈí¼þµÄÓû§ËæÊ±¹Ø×¢³§ÉÌÖ÷Ò³»ò²Î¿¼ÍøÖ·ÒÔ»ñÈ¡½â¾ö·¨×Ó£ºhttps://www.videolan.org/  ¡£


²Î¿¼Á´½Ó


https://news.softpedia.com/news/critical-flaw-in-vlc-media-player-discovered-by-german-cybersecurity-agency-526768.shtml