LevelBlue + SentinelOne Partner to Deliver AI-Powered Managed Security Operations and Incident Response. Learn More

TWSL2013-007: Multiple Vulnerabilities in VLC Media Player - Web Interface

Yesterday, Trustwave SpiderLabs has published an advisory for multiple vulnerabilities in the VLC Media Player web interface. The VLC Media Player is one of the most popular open-source media-player available. About a year ago, VLC reached over a billion downloads and now it's more popular than ever. It is not unusual for media-players to have vulnerabilities, such as buffer, heap and stackoverflows. However, Tanya Secker of Trustwave SpiderLabs discovered that features, such as the web interface could also have security risks too. Tanya discovered a lack of authentication and authorization in the web interface, which will be further addressed in a future VLC release. However, the recent versions currently mitigate against this potential security risk with being able to configure access control lists (ACLs) in the application preferences.

Additionally, Tanya discovered multiple XSS vulnerabilities in the web interface. These vulnerabilities were addressed in 2.0.7 (the latest version of VLC), which is now available at http://www.videolan.org/

 

 

ABOUT LEVELBLUE

LevelBlue secures what's next with intelligence-led security delivering visibility and speed to stop threats faster. As the world’s largest and most analyst-recognized pure-play managed security services provider, our AI-powered managed services and cyber expertise across managed, advisory, and incident response services help clients operate with confidence. Learn more about us.

https://www.levelblue.com/resources/blogs/internal-blog/how-to-create-a-blog-post/

Latest Intelligence

Discover how our specialists can tailor a security program to fit the needs of
your organization.

Request a Demo