yixia / VitamioBundle

Vitamio for Android
http://www.vitamio.org/en/
Other
5.27k stars 2.07k forks source link

Arbitrary code execution caused by Vitamio init function #302

Open giantpune opened 9 years ago

giantpune commented 9 years ago

It was recently disclosed by NowSecure that the Vitamio library contains a serious vulnerability. That blog post details and PoC code to attack a video player using this library. Between the time when an application calls io.vov.vitamio.initialize and when the app plays a media file, another app can replace the native code and take control of the Vitamio one. The same attack works for all apps using Vitamio to play media files.

Fuzion24 commented 9 years ago

:+1:

MythodeaLoL commented 9 years ago

:+1:

dweinstein commented 9 years ago

:+1: