> Does anybody know of any remotely exploitable "root holes" in VLC media > player?
http://www.videolan.org/security/ ALL media players are subject to coding errors since all software projects are so afflicted. Sometimes the authors fix them, sometimes not. Generally it is possible to obtain the patched code only through CVS, SVN, mercurial or some other version control system. Mplayer's coding errors of the past have been patched and the way to get a patched source tree is described at their web site: http://www.mplayerhq.hu/design7/dload.html -- This message posted from opensolaris.org