Home Technology Security advisors say there’s a critical vulnerability in VLC, developers say otherwise

Security advisors say there’s a critical vulnerability in VLC, developers say otherwise

1 min read
6
VLC

VLC is arguably one of the most popular software media players that people use for watching their totally legal home videos and personally ripped copies of their own Blu-rays. It’s also possibly got a massive security flaw – on every version, across every platform except macOS – that could allow attackers to install, modify and even run software without authorisation.

According to German security agency CERT-Bund, there’s a critical vulnerability (CVE-2019-13615) in the ubiquitous media player that’s yet to be patched. As said, it allows for RCE (Remote Code Execution) of unsigned code, along with using it to “disclose files on the host system.”

It doesn’t seem as if the vulnerability has been used by nefarious sorts yet, but given the software’s ubiquity, there’s a staggering a number of potentially unsecured systems.

Developer VideoLAN is aware of the issue – but they suggest that the flaw isn’t reproducible in the current version of VLC. They also suggest that at most, the issue causes a memory leak, which can then lead to poor performance.

Anyway, it seems a new patch is still quite far out. The attack vector appears to be a malformed video file in MKV format, which means that those most at risk are people download and playing unsavoury MKV videos from the internet. Because the patch is still a way out, the recommended solution right now is to just uninstall VLC and use something else in the meantime, or just not be daft enough to play MKV files you’ve torrented.

Last Updated: July 24, 2019

6 Comments

  1. Pariah

    July 24, 2019 at 15:39

    I install the Klite codec pack and use Media Player Classic. Fuck VLC.

    Reply

    • Kromas

      July 24, 2019 at 15:40

      Fuck me! Something we both agree 100% on!

      Reply

    • Guz

      July 24, 2019 at 17:12

      I got a virus once from a “klite” pack, granted I did download it from some random site when i was but a young noob on da interwebz, didn’t know better what could a laitie to do

      Reply

    • Guz

      July 24, 2019 at 17:12

      I got a virus once from a “klite” pack, granted I did download it from some random site when i was but a young noob on da interwebz, didn’t know better what could a laitie to do

      Reply

  2. Guz

    July 24, 2019 at 17:11

    Pretty dick move to publish the security flaw with out contacting VideoLan first, but hey anything for da clickz

    Reply

  3. Gavin Mannion

    July 25, 2019 at 08:25

    good, I hope all the pirates out there have their machines taken over by hackers…

    Reply

Leave a Reply

Your email address will not be published. Required fields are marked *

Check Also

Destiny 2 players are using a Guardian Games exploit to farm infinite Legendary Shards

Now that the Guardian Games have begun, Destiny 2 players have figured out a way to abuse …