Filing as Unconfirmed for now, needs verification: http://www.milw0rm.com/exploits/9427 # VLC Media Player 1.0.0\1.0.1 smb:// URI Handling Remote Stack Overflow PoC # Found By: Dr_IDE # Tested: Windows XP SP2 , XP SP3 and Windows 7 RC1 # Thanks: Pankaj Kohli for finding this in 0.8.6f # Original: http://www.milw0rm.com/exploits/9303 http://www.milw0rm.com/exploits/9439 # VLC Media Player 1.0.0\1.0.1 smb:// URI Handling Remote Stack Overflow # Xpl By : Mountassif Moad # Thanks : His0ka - Simo-soft - v4 Team # Original : http://www.milw0rm.com/exploits/9427
I tried to reproduce it with vlc 1.0.1. Only got regular error message. ERROR: string overflow by 1 (1024 - 1023) in safe_strcpy [smb://example.com@www.example.com/foo/#{AABBBBCCCC] So I guess it doesn't work.
CVE-2009-2484 indicates that there was such a vulnerability, but it was limited to Windows. Also very obsolete regardless, fixed since June 2009.