Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Date: Wed, 25 Aug 2010 19:56:57 -0400 (EDT)
From: "Steven M. Christey" <coley@...us.mitre.org>
To: oss-security <oss-security@...ts.openwall.com>
Subject: Re: CVE request: VLC media player - DLL preloading
 vulnerability


We will have one CVE per vulnerable application.  Yes, it's going to be 
very painful.  Roughly, the rationale is: "the product does not protect 
against a common configuration/behavior in its environment."

> VLC was exploitable by loading wintab32.dll, a component request by
> Qt, as shown in http://www.exploit-db.com/exploits/14750/

Use CVE-2010-3124


> There's another possibility with DMO.

Is this a distinct product outside of VLC, or is it just a different 
component / attack vector?


- Steve

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.