Skip to content

udp:// format string vulnerability

The Month of Apple Bugs reported [http://applefun.blogspot.com/2007/01/moab-02-01-2007-vlc-media-player-udp.html MOAB #2 (closed)] today, which is a format string vulnerability in the udp:// protocol. More details on the exploit here:

http://projects.info-pull.com/moab/MOAB-02-01-2007.html

Apparently only tested on Mac OS X 10.4.8 and Windows (XP?).

To upload designs, you'll need to enable LFS and have an admin enable hashed storage. More information