VLC Media Player < 1.1.5 Samba Share Access Module Code Execution (deprecated)
Medium Nessus Network Monitor Plugin ID 5710
SynopsisThe remote host contains an application that allows arbitrary code execution.
DescriptionThe remote host contains VLC player, a multi-media application.
Versions of VLC media player earlier than 1.1.5 are potentially affected by a code execution vulnerability. Due to an error in the declaration of code calling conventions, VLC suffers from a stack smashing attack in the Samba network share access module which could lead to arbitrary code execution. Note that this issue only affects VLC for Windows.
SolutionUpgrade to VLC Media Player version 1.1.5 or later.