- -----------------------------------------------------------------------
Debian LTS Advisory DLA-3216-1              debian-lts@lists.debian.org
https://www.debian.org/lts/security/                      Utkarsh Gupta
December 03, 2022                           https://wiki.debian.org/LTS
- -----------------------------------------------------------------------

Package        : vlc
Version        : 3.0.17.4-0+deb10u2
CVE ID         : CVE-2022-41325

Mitsurugi Heishiro found out that in VLC, multimedia player and streamer,
a potential buffer overflow in the vnc module could trigger remote code
execution if a malicious vnc URL is deliberately played.

For Debian 10 buster, this problem has been fixed in version
3.0.17.4-0+deb10u2.

We recommend that you upgrade your vlc packages.

For the detailed security status of vlc please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/source-package/vlc

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS

Debian LTS: DLA-3216-1: vlc security update

December 3, 2022
Mitsurugi Heishiro found out that in VLC, multimedia player and streamer, a potential buffer overflow in the vnc module could trigger remote code execution if a malicious vnc URL i...

Summary

For Debian 10 buster, this problem has been fixed in version
3.0.17.4-0+deb10u2.

We recommend that you upgrade your vlc packages.

For the detailed security status of vlc please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/source-package/vlc

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS


Severity
Package : vlc
Version : 3.0.17.4-0+deb10u2
CVE ID : CVE-2022-41325

Related News