ie8 fix
madison

Zero Day

Ryan Naraine, Emil Protalinski and Dancho Danchev

Companies bundling spyware, adware with open-source media player

By | July 14, 2011, 11:15am PDT

Summary: VideoLAN named-and-shamed at least 25 companies that are guilty of bundling spyware and adware programs with the highly rated open-source VLC media player.

VideoLAN developer Ludovic Fauvet has come out swinging against companies that bundle adware and spyware with the open-source VLC media player.

“At VideoLAN we’re really fed up with all those websites/companies that are tricking our users to download malware and violate our IP by distributing misleading versions of VLC without conforming to the GPL license,” Fauvet said.

“What bothers us the most is that many of them are bundling VLC with various crapware to monetize it in ways that mislead our users by thinking they’re downloading an original version. This is not acceptable,” he added.follow Ryan Naraine on twitter

Fauvet named-and-shamed at least 25 companies that were guilty of bundling spyware and adware programs with the highly rated open-source media player.

“The result is a poor product that doesn’t work as intended, that can’t be uninstalled and that clearly abuses its users and their privacy. Not to mention that it also discredits our work as volunteers and that it’s time-consuming, time that is not invested in the development,” he argued.

Fauvet called on users to always download the VLC media player from the project’s official website.

Separately, VideoLAN shipped a patch for a pair of “highly critical” security holes that expose users to computer hijack.

  • An integer overflow error when parsing a RealAudio data block within RealMedia (RM) files can be exploited to cause a heap-based buffer overflow.
  • An integer underflow error when parsing the “strf” chunk within AVI files can be exploited to cause a heap-based buffer overflow.

Successful exploitation of the vulnerabilities allows execution of arbitrary code, Secunia said in an advisory.

The vulnerabilities are confirmed in version 1.1.10. Prior versions may also be affected.

Kick off your day with ZDNet's daily e-mail newsletter. It's the freshest tech news and opinion, served hot. Get it.

Topics

Ryan Naraine is a journalist and social media enthusiast specializing in Internet and computer security issues.

Disclosure

Ryan Naraine

The most important disclosure is of my employment with Kaspersky Lab as a member of the global research and analysis team. Kaspersky Lab is a global company specializing in anti-malware and secure content management technologies. I do not own stocks or other investments in any technology company.

Biography

Ryan Naraine

Ryan Naraine is a journalist and social media enthusiast specializing in Internet and computer security issues. He is currently security evangelist at Kaspersky Lab, an anti-malware company with operations around the globe. He is taking a leadership role in developing the company's online community initiative around secure content management technologies.

Prior to joining Kaspersky Lab, Ryan was Editor-at-Large/Security at eWEEK, leading the magazine's and Web site's coverage of Internet and computer security issues and managing the popular SecurityWatch blog, covering the daily threats, vulnerabilities and IT security technologies. He also covered IT security, hacker attacks and secure content management topics for Jupiter Media's internetnetnews.com.

Ryan can be reached at naraine SHIFT 2 gmail.com. For daily updates on Ryan's activities, follow him on Twitter.

37
Comments

Join the conversation!

Just In

RE: Companies bundling spyware, adware with open-source media player
spin498 18th Jul
News flash, don't you people know, the funny blue text in these blogs are links? So when the writer says :?At VideoLAN we?re really fed up with all those websites/companies that are tricking our users to download malware and violate our IP by distributing misleading versions of VLC without conforming to the GPL license,? Fauvet said.

And the Fauvet said. part is blue, that's a link to what Fauvet said.

Or when the writer says: "Fauvet called on users to always download the VLC media player from the project?s official website." And official website is blue, that's a link?
0 Votes
+ -
of those cyber crooks who disgrace FOSS with spyware.
The DOJ should investigate!
0 Votes
+ -
You make me laugh.
dniemczycki 14th Jul
@Linux Geek
Are you the poster clown for Linux?
@dniemczycki

Yep, Linux Geek is the Ronald McDonald of linuxland. Shame really, it's such a nice OS it could well do without the likes. But then I imagine Microsoft is behind HIS posts. The DOJ should investigate.
@dniemczycki

Also, he's using a picture of Sarah Palin as an avatar. I mean, really pushing the clown analogy!
@bargeemike: Linux Geek will complain his Linux computer was hacked by someone at Microsoft [and offer no proof]. happy
@dniemczycki
He's a Micro$oft troll pretending to be a Linux geek
0 Votes
+ -
It's no big deal Linux Geek
William Pharaoh 14th Jul
@Linux Geek
I was told that spyware and adware can't and won't run on Linux, which is why it's so good! wink
@William Pharaoh
You might read through links, the spyware and adware bundled with VLC are directed toward Windows users.
@William Pharaoh
unless by magic, perhaps?

plain
@Mister Spock
Not magical at all, user clicks link and downloads. Windows users are the target.
@Linux Geek : Get a friggen life. Get off your high horse. You're acting childish.
@Gis Bun
Ya, and his high horse is about 6 feet underground!
@Linux Geek You sound like an idiot. No, really, you do.
@Linux Geek Wow! Just WOW!
0 Votes
+ -
Apple App Store version
global.philosopher 14th Jul
If that misguided fool who requested it be taken down from the App Store would change would change his mind then at least one guaranteed true version would be available. That way there would be a good reference point for the App.
I've seen this App run when it is untainted and it is good but on other platforms it is buggy and most likely tainted with Trojan horses.
@global.philosopher What platform do you feel it is good on, vs. buggy on all others? I've seen it work fine on both Windows and Linux.
@global.philosopher
Didn't devs themselfs said that GPL is not compatible with Apples regulations?

Anyway, MS did said that for their own appstore. Apple should do the same.
0 Votes
+ -
Cracked, copied, poorly designed, runs poorly if at all, patched constantly w/o warning or cycle, written with intent to overcome DRM, praised by folks who really believe what Linux Geek is satirizing(?!) - all FOSS seems "mal" to me.

Jus look what the flagship, Firefox has become: a still slow and clumsy imitator of better browsers (and I don't mean Konquerer.)
@pmchefalo@... Sounds like YOU downloaded the bundled VLC Player.

Good you for being so trusting of software not direct from the source.
@pmchefalo@...
Firefox slow and clumsy?? Its the fastest browser out every speed test I run it beats chrome and it has the biggest growth.
@pmchefalo@... "Cracked, copied, poorly designed" etc.

I guess that explains why the overwhelming majority of web servers out there are using Apache? (source: Netcraft). Or maybe that's why the router and cable modem in your home are running embedded Linux. Not everything is as black and white as you make it out to be.
@pmchefalo@...
Are you Satirizing? I can't really tell... Otherwise, you are either a troll or an idiot.
0 Votes
+ -
VLC in corporate
p.vinnie@... 15th Jul
We are planning to replace all sort of media players such as Windows and Real by installing VLC media player.
It loads fast, can play virtually every file irrespective of CODEC used and can be easily bundled with OS image.
They should digitally sign their installers
I have never found a good original clean version of vlc player since it has been released.Does anyone know where to get an original virgin version anyways??
@Fletchguy I dunno maybe if you read the article it might help? (That's a hint in case you missed it)
@Fletchguy
You will get the real thing from:
http://www.videolan.org/
They have the clean version.
They are the ones that make it.
Where is the list of 25 companies, and also...

Chili's?
0 Votes
+ -
Back to the subject:
john@... 15th Jul
Malware companies are attaching c&*p to decent FOSS applications. VLC is a great replacement for the MS media player. This is a case of the wolves pulling down the elk. What is addressed here is how a "grey" type industry is pulling down innovative products. Forget waiting for the DOJ, we need to find ways of dealing with these "bundling companies" ourselves. BTW, while I can't vouch for the other versions of VLC, the Windows version is very nice. How many responders here actually have used the app?
@john@... I run VLC on all my boxes, Mac, Win7, Linux Mint. It works the same on all of them, that is, great.
In a couple of my classes where I ask (usually older adult) students to type in the URL for VLC, they instead type it into the Google search. Then they inevitably go to some sheister site that tries to leverage the free program with crap. This happens even when I WARN them BEFOREHAND what to do. Lazy brains. It's a jungle out their and they are not paying attention.
so, WHO ARE those websites/companies?
@gioroc The part of the article where the link-styled text is "Fauvet said" links to
http://blog.l0cal.com/2011/07/07/these-companies-that-mislead-our-users/
And the list is there.
I use Linux and I STILL only get VLC from their own web page. happy For some reason openSUSE now insists users use the version in the 3rd party Packman repository instead, suggesting the official version will cause problems, although in my experience it's been just fine (in fact I had a small problem with the version in Packman instead).

Hmm... Linuxgeek - openSUSE is affliated with SUSE which before being bought by Attachmate was owned by Novell who had a deal with Microsoft. Maybe the DOJ should investigate? happy
0 Votes
+ -
Why didn't you list the 25 companies, or provide a link to the list that aleady was published? Know your enemies!
News flash, don't you people know, the funny blue text in these blogs are links? So when the writer says :?At VideoLAN we?re really fed up with all those websites/companies that are tricking our users to download malware and violate our IP by distributing misleading versions of VLC without conforming to the GPL license,? Fauvet said.

And the Fauvet said. part is blue, that's a link to what Fauvet said.

Or when the writer says: "Fauvet called on users to always download the VLC media player from the project?s official website." And official website is blue, that's a link?

Join the conversation!

Formatting +
BB Codes - Note: HTML is not supported in forums
  • [b] Bold [/b]
  • [i] Italic [/i]
  • [u] Underline [/u]
  • [s] Strikethrough [/s]
  • [q] "Quote" [/q]
  • [ol][*] 1. Ordered List [/ol]
  • [ul][*] · Unordered List [/ul]
  • [pre] Preformat [/pre]
  • [quote] "Blockquote" [/quote]
ie8 fix
Click Here
ie8 fix

The best of ZDNet, delivered

ZDNet Newsletters

Get the best of ZDNet delivered straight to your inbox

Facebook Activity

White Papers, Webcasts, & Resources
ie8 fix
ie8 fix