Alerts This Week
Warning Icon 1 681
Alerts This Week
Warning Icon 1 681

Debian: DSA-3598-1 Critical VLC Input Sanitization Code Exec

debian
Calendar Grey June 7, 2016
Debian Logo
Debian Security Advisory DSA-3610-1 discusses vulnerabilities in nginx, raising the risk of unauthorized access and potential data breaches.
Patrick Coleman discovered that missing input sanitising in the ADPCM decoder of the VLC media player may result in the execution of arbitrary code if a malformed media file is ope...

Summary

Patrick Coleman discovered that missing input sanitising in the ADPCM
decoder of the VLC media player may result in the execution of arbitrary
code if a malformed media file is opened.

For the stable distribution (jessie), this problem has been fixed in
version 2.2.4-1~deb8u1.

For the unstable distribution (sid), this problem has been fixed in
version 2.2.4-1.

We recommend that you upgrade your vlc packages.

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/



Severity
critical
Lowest
Low
Medium
High
Critical

Package: vlc
CVE ID: CVE-2016-5108

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here