Intego News > Press Releases

 

INTEGO SECURITY MEMO - JANUARY 3, 2007
VLC Media Player "udp://" URI Handling Format String Vulnerability

 

Exploit: OSX.m3udp.gen - VLC Media Player "udp://" URI Handling Format String Vulnerability

Discovered: January 2, 2007

Risk: Highly critical

Description: This proof-of-concept exploit, which has not yet been seen in the wild, takes advantage of a vulnerability in the way VLC handles udp:// URIs. This exploit, which can be activated via web sites or M3U files, can allow for execution of specially crafted code.

Means of protection: Intego VirusBarrier X and VirusBarrier X4 with virus definitions dated January 3, 2007 or later, protects against this exploit. Users are also advised to not launch M3U files from untrusted sources. Users who use VLC Media Player are advised to check the program's web site for updates.



About Intego

Intego develops and sells Internet security and privacy software exclusively for Macs and iOS devices.

Intego provides the widest range of software to protect users and their Macs and iOS devices from the dangers of the Internet. Intego's multilingual software and support regularly receives awards from Mac magazines, and protects more than one million users in over 100 countries. Intego has headquarters in the USA, France and Japan. For further information, visit www.intego.com.

 

 

mac antivirus and security software
mac malware protection

home | contact