Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

Mageia: 2024-0007 moderate: VLC heap overflow and underflow issues

mageia
Calendar Grey January 14, 2024
Dist Mageia Esm H88
Mageia 2024-0007 addresses VLC heap overflow issues to prevent memory corruption vulnerabilities.
The updated packages fix security vulnerabilities: Videolan VLC prior to version 3.0.20 contains an incorrect offset read that leads to a Heap-Based Buffer Overflow in function Get...

Summary

The updated packages fix security vulnerabilities: Videolan VLC prior to version 3.0.20 contains an incorrect offset read that leads to a Heap-Based Buffer Overflow in function GetPacket() and results in a memory corruption (CVE-2023-47359). Videolan VLC prior to version 3.0.20 contains an Integer underflow that leads to an incorrect packet length (CVE-2023-47360).

References

- https://bugs.mageia.org/show_bug.cgi?id=32487

- https://lwn.net/Articles/950049/

- https://www.cve.org/CVERecord?id=CVE-2023-47359

- https://www.cve.org/CVERecord?id=CVE-2023-47360

Resolution

SRPMS

- 9/core/vlc-3.0.20-1.mga9

- 9/tainted/vlc-3.0.20-1.mga9.tainted

Publication date: 14 Jan 2024
URL: https://advisories.mageia.org/MGASA-2024-0007.html
Type: security
CVE: CVE-2023-47359, CVE-2023-47360

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here