VLC < 2.0.7 Multiple Vulnerabilities
Medium Nessus Plugin ID 69015
SynopsisThe remote Windows host contains a media player that is affected by multiple vulnerabilities.
DescriptionThe version of VLC media player installed on the remote host is earlier than 2.0.7 and is, therefore, affected by the following vulnerabilities:
- The web interface contains a flaw that does not validate input passed via XML services resulting in a cross-site scripting vulnerability.
- A flaw exists in the XML services of the web interface that may allow a remote attacker to execute media player commands.
- A flaw exists that could lead to a denial of service / memory consumption when loading a malicious playlist.
SolutionUpgrade to VLC version 2.0.7 or later.