Alerts This Week
Warning Icon 1 687
Alerts This Week
Warning Icon 1 687

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":546,"type":"x","order":1,"pct":78.45,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.31,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.36,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -3 articles for you...
89

Fedora 38: 2023-a5e10b188a Critical: mpv Update Addresses Security Concerns

FFmpeg 6.0 upgrade. ---- update to 111.0.5563.64. Fixes the following security issues: CVE-2023-0927 CVE-2023-0928 CVE-2023-0929 CVE-2023-0930 CVE-2023-0931 CVE-2023-0932 CVE-2023-0933 CVE-2023-0941 CVE-2023-1213 CVE-2023-1214 CVE-2023-1215 CVE-2023-1216 CVE-2023-1217 CVE-2023-1218 CVE-2023-1219 CVE-2023-1220 CVE-2023-1221 CVE-2023-1222 CVE-2023-1223. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2023-a5e10b188a 2023-03-14 00:16:44.047436 --------------------------------------------------------------------------------Name : mpv Product : Fedora 38 Version : 0.35.1 Release : 3.fc38 URL : https://mpv.io/ Summary : Movie player playing most video formats and DVDs Description : Mpv is a movie player based on MPlayer and mplayer2. It supports a wide variety of video file formats, audio and video codecs, and subtitle types. Special input URL types are available to read input from a variety of sources other than disk files. Depending on platform, a variety of different video and audio output methods are supported. Mpv has an OpenGL, Vulkan, and D3D11 based video output that is capable of many features loved by videophiles, such as video scaling with popular high quality algorithms, color management, frame timing, interpolation, HDR, and more. While mpv strives for minimalism and provides no real GUI, it has a small controller on top of the video for basic control. Mpv can leverage most hardware decoding APIs on all platforms. Hardware decoding can be enabled at runtime on demand. Powerful scripting capabilities can make the player do almost anything. There is a large selection of user scripts on the wiki. A straightforward C API was designed from the ground up to make mpv usable as a library and facilitate easy integration into other applications. --------------------------------------------------------------------------------Update Information: FFmpeg 6.0 upgrade. ---- update to 111.0.5563.64. Fixes the following security issues: CVE-2023-0927 CVE-2023-0928 CVE-2023-0929 CVE-2023-0930 CVE-2023-0931 CVE-2023-0932 CVE-2023-0933 CVE-2023-0941 CVE-2023-1213 CVE-2023-1214 CVE-2023-1215 CVE-2023-1216 CVE-2023-1217 CVE-2023-1218 CVE-2023-1219 CVE-2023-1220 CVE-2023-1221 CVE-2023-1222 CVE-2023-1223 CVE-2023-1224 CVE-2023-1225 CVE-2023-1226 CVE-2023-1227 --------------------------------------------------------------------------------ChangeLog: * Sun Mar 12 2023 Neal Gompa - 0.35.1-3 - Rebuild for ffmpeg 6.0 --------------------------------------------------------------------------------References: [ 1 ] Bug #1944122 - notcurses-2.3.17 is available https://bugzilla.redhat.com/show_bug.cgi?id=1944122 [ 2 ] Bug #2022640 - notcurses-2.4.9 is available https://bugzilla.redhat.com/show_bug.cgi?id=2022640 [ 3 ] Bug #2028587 - notcurses-3.0.4 is available https://bugzilla.redhat.com/show_bug.cgi?id=2028587 [ 4 ] Bug #2045133 - notcurses: FTBFS in Fedora rawhide/f36 https://bugzilla.redhat.com/show_bug.cgi?id=2045133 [ 5 ] Bug #2053373 - notcurses-3.0.6 is available https://bugzilla.redhat.com/show_bug.cgi?id=2053373 [ 6 ] Bug #2172934 - CVE-2023-0927 CVE-2023-0928 CVE-2023-0929 CVE-2023-0930 CVE-2023-0931 CVE-2023-0932 CVE-2023-0933 CVE-2023-0941 chromium: various flaws [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2172934 [ 7 ] Bug #2173846 - ffmpeg-6.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2173846 [ 8 ] Bug #2174875 - k3b-22.12.3 is available https://bugzilla.redhat.com/show_bug.cgi?id=2174875 [ 9 ] Bug #2176135 - mlt-7.14.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2176135 [ 10 ] Bug #2176519 - CVE-2023-1213 CVE-2023-1214 CVE-2023-1215 CVE-2023-1216 CVE-2023-1217 CVE-2023-1218 CVE-2023-1219 CVE-2023-1220 CVE-2023-1221 CVE-2023-1222 CVE-2023-1223 CVE-2023-1224 CVE-2023-1225 CVE-2023-1226 CVE-2023-1227 ... chromium:various flaws [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2176519 [ 11 ] Bug #2176520 - CVE-2023-1213 CVE-2023-1214 CVE-2023-1215 CVE-2023-1216 CVE-2023-1217 CVE-2023-1218 CVE-2023-1219 CVE-2023-1220 CVE-2023-1221 CVE-2023-1222 CVE-2023-1223 CVE-2023-1224 CVE-2023-1225 CVE-2023-1226 CVE-2023-1227 ... chromium: various flaws [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2176520 [ 12 ] Bug #2177300 - retroarch-1.15.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2177300 [ 13 ] Bug #2177550 - nv-codec-headers-12.0.16.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2177550 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-a5e10b188a' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam, report it: . Transition to mpv version 0.35.1 on Fedora 38, addressing various security vulnerabilities for enhanced stability in your multimedia sessions.. mpv security issues, Fedora software update, multimedia player vulnerabilities, FFmpeg upgrade. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Mar 14, 2023 Critical Fedora
197

Debian Buster: DLA-3358-1 Critical: Mpv Use After Free Risk

An issue has been found in mpv, a video player based on MPlayer/mplayer2. Due to a use after free an attacker coudl execute arbitrary code or crash the program via the ao_c parameter. . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3358-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Thorsten Alteholz March 12, 2023 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : mpv Version : 0.29.1-1+deb10u1 CVE ID : CVE-2020-19824 An issue has been found in mpv, a video player based on MPlayer/mplayer2. Due to a use after free an attacker coudl execute arbitrary code or crash the program via the ao_c parameter. For Debian 10 buster, this problem has been fixed in version 0.29.1-1+deb10u1. We recommend that you upgrade your mpv packages. For the detailed security status of mpv please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/mpv Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Responding to a critical vulnerability in Debian LTS associated with mpv that permits malicious entities to run unauthorized code or destabilize the media player.. debian buster security, mpv execution risk, LTS advisory update. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Mar 11, 2023 Critical Debian LTS
91

Gentoo: GLSA-202107-46 Normal: mpv Format String Code Execution

A format string vulnerability was found in mpv, potentially resulting in arbitrary code execution.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202107-46 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: mpv: Format string vulnerability Date: July 20, 2021 Bugs: #780474 ID: 202107-46 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= A format string vulnerability was found in mpv, potentially resulting in arbitrary code execution. Background ========= Video player based on MPlayer/mplayer2. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 media-video/mpv < 0.33.1 > = 0.33.1 Description ========== mpv uses untrusted input within format strings. Impact ===== A remote attacker could entice a user to open a specially crafted m3u playlist file using mpv, possibly resulting in execution of arbitrary code with the privileges of the process or a Denial of Service condition. Workaround ========= There is no known workaround at this time. Resolution ========= All mpv users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =media-video/mpv-0.33.1" References ========= [ 1 ] CVE-2021-30145 https://nvd.nist.gov/vuln/detail/CVE-2021-30145 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202107-46 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality andsecurity of our users' machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org. License ====== Copyright 2021 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.5/ . An issue with format strings in mpv may allow for remote code execution. Users are advised to upgrade promptly to maintain security.. mpv Format String,Gentoo Security Advisory,Software Hazard,Code Execution Risk. . LinuxSecurity.com Team

Calendar 2 Jul 20, 2021 Gentoo
202

openSUSE: 2021:0800-1 Critical: VLC Media Player Vulnerability

An update that fixes one vulnerability is now available. . openSUSE Security Update: Security update for mpv ______________________________________________________________________________ Announcement ID: openSUSE-SU-2021:0798-1 Rating: important References: #1186230 Cross-References: CVE-2021-30145 CVSS scores: CVE-2021-30145 (NVD) : 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Affected Products: openSUSE Backports SLE-15-SP2 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for mpv fixes the following issues: - CVE-2021-30145: Fixed format string vulnerability allows user-assisted remote attackers to achieve code execution via a crafted m3u playlist file (boo#1186230) This update was imported from the openSUSE:Leap:15.2:Update update project. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP2: zypper in -t patch openSUSE-2021-798=1 Package List: - openSUSE Backports SLE-15-SP2 (aarch64 ppc64le s390x x86_64): libmpv1-0.32.0+git.20200301T004003.e7bab0025f-bp152.2.6.1 mpv-0.32.0+git.20200301T004003.e7bab0025f-bp152.2.6.1 mpv-devel-0.32.0+git.20200301T004003.e7bab0025f-bp152.2.6.1 - openSUSE Backports SLE-15-SP2 (noarch): mpv-bash-completion-0.32.0+git.20200301T004003.e7bab0025f-bp152.2.6.1 mpv-zsh-completion-0.32.0+git.20200301T004003.e7bab0025f-bp152.2.6.1 References: https://www.suse.com/security/cve/CVE-2021-30145.html https://bugzilla.suse.com/1186230 . Critical patch release for Fedora addressing ffmpeg issue. Essential update code: FEDORA-SU-2023:0456-1.. openSUSE Security, mpv Update, Important Patch, Remote Code Execution,Format String Issue. . Severity: Important. LinuxSecurity.com Team

Calendar 2 May 27, 2021 Important OpenSUSE
202

openSUSE Leap 15.3: 2021:1234-2 Crucial Vulnerability Patch

An update that fixes one vulnerability is now available. . openSUSE Security Update: Security update for mpv ______________________________________________________________________________ Announcement ID: openSUSE-SU-2021:0788-1 Rating: important References: #1186230 Cross-References: CVE-2021-30145 Affected Products: openSUSE Leap 15.2 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for mpv fixes the following issues: - CVE-2021-30145: Fixed format string vulnerability allows user-assisted remote attackers to achieve code execution via a crafted m3u playlist file (boo#1186230) Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.2: zypper in -t patch openSUSE-2021-788=1 Package List: - openSUSE Leap 15.2 (x86_64): libmpv1-0.32.0+git.20200301T004003.e7bab0025f-lp152.2.6.1 libmpv1-debuginfo-0.32.0+git.20200301T004003.e7bab0025f-lp152.2.6.1 mpv-0.32.0+git.20200301T004003.e7bab0025f-lp152.2.6.1 mpv-debuginfo-0.32.0+git.20200301T004003.e7bab0025f-lp152.2.6.1 mpv-debugsource-0.32.0+git.20200301T004003.e7bab0025f-lp152.2.6.1 mpv-devel-0.32.0+git.20200301T004003.e7bab0025f-lp152.2.6.1 - openSUSE Leap 15.2 (noarch): mpv-bash-completion-0.32.0+git.20200301T004003.e7bab0025f-lp152.2.6.1 mpv-zsh-completion-0.32.0+git.20200301T004003.e7bab0025f-lp152.2.6.1 References: https://www.suse.com/security/cve/CVE-2021-30145.html https://bugzilla.suse.com/1186230 . openSUSE publishes crucial security patch for mpv addressing a critical code execution vulnerability linked to format string defects.. openSUSE Security Update, mpv Code Execution, Software Patch. . Severity:Important. LinuxSecurity.com Team

Calendar 2 May 24, 2021 Important OpenSUSE
91

Gentoo: GLSA 201805-05 High Risk of Code Execution in mpv Software

A vulnerability has been found in mpv that may allow a remote attacker to execute arbitrary code.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 201805-05 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: High Title: mpv: Remote code execution Date: May 14, 2018 Bugs: #646886 ID: 201805-05 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= A vulnerability has been found in mpv that may allow a remote attacker to execute arbitrary code. Background ========= Video player based on MPlayer/mplayer2 Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 media-video/mpv < 0.27.2 > = 0.27.2 Description ========== A vulnerability was discovered in mpv with the handling of HTML documents containing VIDEO elements. Additionally, mpv accepts arbitrary URLs in a src attribute without a protocol whitelist in player/lua/ytdl_hook.lua. Impact ===== A remote attacker, by enticing the user to visit a specially crafted web site, could execute arbitrary code. Workaround ========= There is no known workaround at this time. Resolution ========= All mpv users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =media-video/mpv-0.27.2" References ========= [ 1 ] CVE-2018-6360 https://nvd.nist.gov/vuln/detail/CVE-2018-6360 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/201805-05 Concerns? ======== Security is a primary focusof Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org. License ====== Copyright 2018 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.5/ . Important Gentoo notice GLSA 202110-12 for VLC informs about a severe vulnerability that could allow for remote code execution.. mpv Security Advisory,Gentoo Remote Execution,Code Execution Risk. . LinuxSecurity.com Team

Calendar 2 May 14, 2018 Gentoo
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":546,"type":"x","order":1,"pct":78.45,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.31,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.36,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here