VideoLAN VLC media player »º³åÇø¹ýʧÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2019-07-22

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-13615 £¬Î£ÏÕ¼¶±ð£ºÑÏÖØ £¬CVSS·ÖÖµ£º9.8


Ó°Ïì°æ±¾


ÊÜÓ°ÏìµÄ°æ±¾


VideoLAN VLC media player 3.0.7.1


Îó²î¸ÅÊö


VideoLAN VLC media playerÊÇ·¨¹úVideoLAN×éÖ¯µÄÒ»¿îÃâ·Ñ¡¢¿ªÔ´µÄ¿çƽ̨¶àýÌå²¥·ÅÆ÷£¨Ò²ÊÇÒ»¸ö¶àýÌå¿ò¼Ü£© ¡£¸Ã²úÆ·Ö§³Ö²¥·Å¶àÖÖ½éÖÊ£¨Îļþ¡¢¹âÅ̵ȣ©¡¢¶àÖÖÒôÊÓÆµÃûÌã¨WMV,MP3µÈ£©µÈ ¡£


VideoLAN VLC media player 3.0.7.1°æ±¾ÖеÄmodules/demux/mkv/demux.cppÎļþµÄmkv::demux_sys_t::FreeUnused()±£´æ»º³åÇø¹ýʧÎó²î ¡£¸ÃÎó²îÔ´ÓÚÍøÂçϵͳ»ò²úÆ·ÔÚÄÚ´æÉÏÖ´ÐвÙ×÷ʱ £¬Î´×¼È·ÑéÖ¤Êý¾Ý½çÏß £¬µ¼ÖÂÏò¹ØÁªµÄÆäËûÄÚ´æÎ»ÖÃÉÏÖ´ÐÐÁ˹ýʧµÄ¶Áд²Ù×÷ ¡£¹¥»÷Õß¿ÉʹÓøÃÎó²îµ¼Ö»º³åÇøÒç³ö»ò¶ÑÒç³öµÈ ¡£ 


Îó²îÑéÖ¤


ÔÝÎÞPOC/EXP ¡£ 


ÐÞ¸´½¨Òé


ÏÖÔÚ³§ÉÌÔÝδÐû²¼ÐÞ¸´²½·¥½â¾ö´ËÇå¾²ÎÊÌâ £¬½¨ÒéʹÓôËÈí¼þµÄÓû§ËæÊ±¹Ø×¢³§ÉÌÖ÷Ò³»ò²Î¿¼ÍøÖ·ÒÔ»ñÈ¡½â¾ö²½·¥£ºhttps://www.videolan.org/ ¡£


²Î¿¼Á´½Ó


https://news.softpedia.com/news/critical-flaw-in-vlc-media-player-discovered-by-german-cybersecurity-agency-526768.shtml