VideoLAN has released VLC Media Player 1.1.10 to address an integer overflow vulnerability in the xspf demuxer. Exploitation of this vulnerability may allow an attacker to execute arbitrary code.
US-CERT encourages users and administrators to review the release notes for VLC Media Player 1.1.10 and apply any necessary updates to help mitigate the risks.