The updated packages fix security vulnerabilities:
Videolan VLC prior to version 3.0.20 contains an incorrect offset read
that leads to a Heap-Based Buffer Overflow in function GetPacket() and
results in a memory corruption (CVE-2023-47359).
Videolan VLC prior to version 3.0.20 contains an Integer underflow that
leads to an incorrect packet length (CVE-2023-47360).
- https://bugs.mageia.org/show_bug.cgi?id=32487
- https://lwn.net/Articles/950049/
- https://www.cve.org/CVERecord?id=CVE-2023-47359
- https://www.cve.org/CVERecord?id=CVE-2023-47360
- 9/core/vlc-3.0.20-1.mga9
- 9/tainted/vlc-3.0.20-1.mga9.tainted
Get the latest Linux and open source security news straight to your inbox.