Debian Security Advisory 1819-1 - Several vulnerabilities have been discovered in vlc, a multimedia player and streamer.
7827ca0570fa45743fb8336eab394c44bf38311c688135f7bd9b204c89d50949
Gentoo Linux Security Advisory GLSA 200807-13 - Remi Denis-Courmont reported that VLC loads plugins from the current working directory in an unsafe manner. Versions less than 0.8.6i are affected.
704516c3977bd41907e153237008613021d592964b19a35792dae3c1b50b3264
Secunia Research has discovered a vulnerability in VLC Media Player versions 0.8.6h on Windows, which can be exploited by malicious people to compromise a user's system. The vulnerability is caused due to an integer overflow error within the "Open()" function in modules/demux/wav.c. This can be exploited to cause a heap-based buffer overflow via a specially crafted WAV file having an overly large "fmt" chunk.
e2f38b98275bda496b754a264185e18e366d990b4a6ce34468c89d7f4314050d