This script is Copyright (C) 2012-2014 Tenable Network Security, Inc.
The remote Windows host contains a media player that is affected by a
code execution vulnerability.
The version of VLC installed on the remote host is 0.x later than 0.9.0
or 1.x earlier than or equal to 1.1.12. It, therefore, contains a
double-free error in the function 'get_chunk_header' in the file
'modules/demux/ty.c'. This error can be exploited by a specially
crafted TiVo (TY) file, which could lead to remote arbitrary code
See also :
Upgrade to VLC version 1.1.13 / 2.0.0 or later. Alternatively, remove
any affected plugin files from VLC's plugins directory.
Risk factor :
High / CVSS Base Score : 9.3
CVSS Temporal Score : 8.1
Public Exploit Available : false