Alerts This Week
Warning Icon 1 631
Alerts This Week
Warning Icon 1 631

Mageia: 2018-0400 Critical Update: VLC Use-After-Free Issue

mageia
Calendar Grey October 19, 2018
Dist Mageia Esm H88
Debian: 2022-0605 urgent: gnome-shell buffer-overflow patch to prevent potential security breach.
This update provides vlc 3.0.4 and fixes atleast the following security issue: A use-after-free was discovered in the MP4 demuxer of the VLC media player, which could result in th...

Summary

This update provides vlc 3.0.4 and fixes atleast the following security issue:
A use-after-free was discovered in the MP4 demuxer of the VLC media player, which could result in the execution of arbitrary code if a malformed media file is played (CVE-2018-11529)
For other fixes in this update, see the referenced NEWS.

References

- https://bugs.mageia.org/show_bug.cgi?id=23092

- https://lists.debian.org/debian-security-announce/2018/msg00180.html

- https://code.videolan.org/videolan/vlc-3.0/-/raw/master/NEWS

- https://www.cve.org/CVERecord?id=CVE-2018-11529

Resolution

SRPMS

- 6/tainted/vlc-3.0.4-1.mga6.tainted

- 6/core/vlc-3.0.4-1.mga6

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 19 Oct 2018
URL: https://advisories.mageia.org/MGASA-2018-0400.html
Type: security
CVE: CVE-2018-11529

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here