Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

Gentoo: GLSA-201603-08 Normal: VLC Multiple Risks and Code Execution

gentoo
Calendar Grey March 12, 2016
Dist Gentoo Esm H88
Gentoo GLSA 202303-09 addresses severe vulnerabilities in VLC that could lead to unauthorized remote code execution and denial-of-service (DoS) attacks. Users should upgrade without delay
Multiple vulnerabilities have been found in VLC allowing remote attackers to execute arbitrary code or cause Denial of Service.

Summary

Multiple vulnerabilities have been discovered in VLC. Please review the CVE identifiers referenced below for details.

Resolution

All VLC users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose ">=media-video/vlc-2.2.1-r1"

References

[ 1 ] CVE-2014-1684 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-1684 [ 2 ] CVE-2014-6440 https://www.cve.org/CVERecord?id=CVE-2014-6440 [ 3 ] CVE-2014-9597 https://www.cve.org/CVERecord?id=CVE-2014-9597 [ 4 ] CVE-2014-9598 https://www.cve.org/CVERecord?id=CVE-2014-9598 [ 5 ] CVE-2014-9625 https://www.cve.org/CVERecord?id=CVE-2014-9625 [ 6 ] CVE-2014-9626 https://www.cve.org/CVERecord?id=CVE-2014-9626 [ 7 ] CVE-2014-9627 https://www.cve.org/CVERecord?id=CVE-2014-9627 [ 8 ] CVE-2014-9628 https://www.cve.org/CVERecord?id=CVE-2014-9628 [ 9 ] CVE-2014-9629 https://www.cve.org/CVERecord?id=CVE-2014-9629 [ 10 ] CVE-2014-9630 https://www.cve.org/CVERecord?id=CVE-2014-9630 [ 11 ] CVE-2015-1202 https://www.cve.org/CVERecord?id=CVE-2015-1202 [ 12 ] CVE-2015-1203 https://www.cve.org/CVERecord?id=CVE-2015-1203 [ 13 ] CVE-2015-5949 https://www.cve.org/CVERecord?id=CVE-2015-5949 [ 14 ] CVE-2015-594...

Read the Full Advisory

Availability

This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/201603-08
style>.gentoo_availability{display:block;}

Concerns

Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to security@gentoo.org or alternatively, you may file a bug at https://bugs.gentoo.org.

Severity: Normal
Title: VLC: Multiple vulnerabilities
Date: March 12, 2016
Bugs: #534532, #537154, #542222, #558418
ID: 201603-08

Synopsis

Multiple vulnerabilities have been found in VLC allowing remote attackers to execute arbitrary code or cause Denial of Service.

Background

VLC is a cross-platform media player and streaming server.

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Affected Packages

------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 media-video/vlc < 2.2.1-r1 >= 2.2.1-r1

Impact

===== Remote attackers could possibly execute arbitrary code or cause Denial of Service.

Workaround

There is no known work around at this time.

Related News

Your message here