Jump to content

VLC / streaming - vulnerabilities - malicious subtitle files


Goku22

Recommended Posts

I just came across this news on a other website and i thought i'd share it here with everyone so everybody can take precautions.

 

It seems popular streaming platforms such as VLC, Kodi (XBMC), Popcorn-Time and strem.io have vulnerabilities.

Check Point researchers revealed a new attack vector which threatens millions of users worldwide – attack by subtitles.

Apparently it is possible to craft malicious subtitle files which can be included with any video.
When an victim’s media player plays ore downloads a subtitle file through a streaming device the attackers can take complete control over the device.

 

Here's a link to the full article:

http://blog.checkpoint.com/2017/05/23/hacked-in-translation/

 

Kodi, VLC, Popcorn Time and Stremio are the platforms on which the researchers tested their hack, but they expect that many other media players are also vulnerable.

The aforementioned parties are informed in advance and have the vulnerabilities according to Check Point already partially solved, while further research is done.

VLC and Stremio have updated their software released to fix the vulnerability.

The team behind Kodi will have the vulnerability being addressed in version 17.2

 

For users of VLC: be sure to check manually if your version number is version 2.2.6 sins it doesn't always update to the latest right away.

 

Edited by Goku22
Link to comment
Share on other sites

The flaw seems to stem from the way certain players handle automatically extracting subtitles from .zip archives. As long as you use only embedded subs and/or .ass/.srt files the vulnerability isn't relevant.

 

On 2017-5-24 at 6:19 AM, Goku22 said:

they expect that many other media players are also vulnerable

MPC-HC's internal subtitle renderer doesn't seem to be affected by this vulnerability. XySubFilter's dev has left us in the dark since 2015 so no word on whether it's affected yet.

  • Like 1
Link to comment
Share on other sites

  • 1 month later...

Yeah i thought i'd share it here sins subtitles are mostly used with anime series.

Like @MaxxCatt mentioned if you have the latest VLC you are safe. They fixed it already.

Also thanks @Superoswald for clearing that up i wasn't aware this vulnerability was related to only .zip archived subtitles.

Makes sense because it would be pretty strange if someone would be able to embedded malicious stuff in  .ass , .srt files etc.

 

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...
Please Sign In or Sign Up