Telstra has revealed the addition of almost one million new mobile services in the six months to December 2011, but Sensis revenues plummeted 24 percent in 12 months.
read more
Stephen Withers
Wednesday, 03 January 2007 04:44
"By supplying a specially crafted string [to the udp:// URL handler], a remote attacker could cause an arbitrary code execution condition, under the privileges of the user running VLC."
Given that VLC is an Open Source project, we would expect a fix to be released shortly. For now, we'll just be especially careful about the files and playlists we open with this application.
In related news, Landon Fuller has created and released a patch to fix the QuickTime RTSP buffer overflow that was the subject of MoAB #1. The patch requires Unsanity's free Application Enhancer utility. He also notes that disabling the RTSP handler (as suggested by the MoAB team) may not provide protection against exploits as there are other vulnerable entry points.
"If I have time (or assistance), I'll attempt to patch the other vulnerabilities, one a day, until the month is out," writes Fuller.
Loading comments ...

|
Microsoft Office 365Try an easy-to-use set of web-enabled tools for business-class productivity services. Office 365 provides anywhere-access to email, important documents, contacts, and calendars on almost any device. |