An update that solves 7 vulnerabilities and has three fixes is now available.. openSUSE Security Update: Security update for vlc ______________________________________________________________________________ Announcement ID: openSUSE-SU-2019:1909-1 Rating: important References: #1093732 #1094893 #1118586 #1133290 #1138354 #1138933 #1141522 #1142161 #1143547 #1143549 Cross-References: CVE-2018-19857 CVE-2019-12874 CVE-2019-13602 CVE-2019-13962 CVE-2019-5439 CVE-2019-5459 CVE-2019-5460 Affected Products: openSUSE Leap 15.0 ______________________________________________________________________________ An update that solves 7 vulnerabilities and has three fixes is now available. Description: This update for vlc to version 3.0.7.1 fixes the following issues: Security issues fixed: - CVE-2019-5439: Fixed a buffer overflow (bsc#1138354). - CVE-2019-5459: Fixed an integer underflow (bsc#1143549). - CVE-2019-5460: Fixed a double free (bsc#1143547). - CVE-2019-12874: Fixed a double free in zlib_decompress_extra in modules/demux/mkv/util.cpp (bsc#1138933). - CVE-2019-13602: Fixed an integer underflow in mp4 demuxer (boo#1141522). - CVE-2019-13962: Fixed a heap-based buffer over-read in avcodec (boo#1142161). Non-security issues fixed: - Video Output: * Fix hardware acceleration with some AMD drivers * Improve direct3d11 HDR support - Access: * Improve Blu-ray support - Audio output: * Fix pass-through on Android-23 * Fix DirectSound drain - Demux: Improve MP4 support - Video Output: * Fix 12 bits sources playback with Direct3D11 * Fix crash on iOS * Fix midstream aspect-ratio changes when Windows hardware decoding is on * Fix HLG display with Direct3D11 - Stream Output: Improve Chromecast support with new ChromeCast apps - Misc: * Update Youtube, Dailymotion, Vimeo,Soundcloud scripts * Work around busy looping when playing an invalid item with loop enabled - Updated translations. New package libaom: * Initial version 1.0.0 * A library for AOMedia Video 1 (AV1), an open, royalty-free video coding format designed for video transmissions over the Internet. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.0: zypper in -t patch openSUSE-2019-1909=1 Package List: - openSUSE Leap 15.0 (noarch): libaom-devel-doc-1.0.0-lp150.2.1 vlc-lang-3.0.7.1-lp150.8.1 - openSUSE Leap 15.0 (x86_64): aom-tools-1.0.0-lp150.2.1 aom-tools-debuginfo-1.0.0-lp150.2.1 libaom-debugsource-1.0.0-lp150.2.1 libaom-devel-1.0.0-lp150.2.1 libaom0-1.0.0-lp150.2.1 libaom0-debuginfo-1.0.0-lp150.2.1 libvlc5-3.0.7.1-lp150.8.1 libvlc5-debuginfo-3.0.7.1-lp150.8.1 libvlccore9-3.0.7.1-lp150.8.1 libvlccore9-debuginfo-3.0.7.1-lp150.8.1 vlc-3.0.7.1-lp150.8.1 vlc-codec-gstreamer-3.0.7.1-lp150.8.1 vlc-codec-gstreamer-debuginfo-3.0.7.1-lp150.8.1 vlc-debuginfo-3.0.7.1-lp150.8.1 vlc-debugsource-3.0.7.1-lp150.8.1 vlc-devel-3.0.7.1-lp150.8.1 vlc-jack-3.0.7.1-lp150.8.1 vlc-jack-debuginfo-3.0.7.1-lp150.8.1 vlc-noX-3.0.7.1-lp150.8.1 vlc-noX-debuginfo-3.0.7.1-lp150.8.1 vlc-qt-3.0.7.1-lp150.8.1 vlc-qt-debuginfo-3.0.7.1-lp150.8.1 vlc-vdpau-3.0.7.1-lp150.8.1 vlc-vdpau-debuginfo-3.0.7.1-lp150.8.1 References: https://www.suse.com/security/cve/CVE-2018-19857.html https://www.suse.com/security/cve/CVE-2019-12874.html https://www.suse.com/security/cve/CVE-2019-13602.html https://www.suse.com/security/cve/CVE-2019-13962.html https://www.suse.com/security/cve/CVE-2019-5439.html https://www.suse.com/security/cve/CVE-2019-5459.html https://www.suse.com/security/cve/CVE-2019-5460.html https://bugzilla.suse.com/1093732 https://bugzilla.suse.com/1094893 https://bugzilla.suse.com/1118586 https://bugzilla.suse.com/1133290 https://bugzilla.suse.com/1138354 https://bugzilla.suse.com/1138933 https://bugzilla.suse.com/1141522 https://bugzilla.suse.com/1142161 https://bugzilla.suse.com/1143547 https://bugzilla.suse.com/1143549 -- . Enhance address security vulnerabilities in VLC for openSUSE Leap, boosting overall system resilience and media performance.. openSUSE Security Update,VLC fixes,buffers management,integer handling. . Severity: Important. LinuxSecurity.com Team
Multiple vulnerabilities have been found in VLC allowing remote attackers to execute arbitrary code or cause Denial of Service.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 201603-08 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: VLC: Multiple vulnerabilities Date: March 12, 2016 Bugs: #534532, #537154, #542222, #558418 ID: 201603-08 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Multiple vulnerabilities have been found in VLC allowing remote attackers to execute arbitrary code or cause Denial of Service. Background ========= VLC is a cross-platform media player and streaming server. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 media-video/vlc < 2.2.1-r1 > = 2.2.1-r1 Description ========== Multiple vulnerabilities have been discovered in VLC. Please review the CVE identifiers referenced below for details. Impact ===== Remote attackers could possibly execute arbitrary code or cause Denial of Service. Workaround ========= There is no known work around at this time. Resolution ========= All VLC users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =media-video/vlc-2.2.1-r1" References ========= [ 1 ] CVE-2014-1684 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-1684 [ 2 ] CVE-2014-6440 https://www.cve.org/CVERecord?id=CVE-2014-6440 [ 3 ] CVE-2014-9597 https://www.cve.org/CVERecord?id=CVE-2014-9597 [ 4 ] CVE-2014-9598 https://www.cve.org/CVERecord?id=CVE-2014-9598 [ 5 ] CVE-2014-9625 https://www.cve.org/CVERecord?id=CVE-2014-9625 [ 6 ] CVE-2014-9626 https://www.cve.org/CVERecord?id=CVE-2014-9626 [ 7 ] CVE-2014-9627 https://www.cve.org/CVERecord?id=CVE-2014-9627 [ 8 ] CVE-2014-9628 https://www.cve.org/CVERecord?id=CVE-2014-9628 [ 9 ] CVE-2014-9629 https://www.cve.org/CVERecord?id=CVE-2014-9629 [ 10 ] CVE-2014-9630 https://www.cve.org/CVERecord?id=CVE-2014-9630 [ 11 ] CVE-2015-1202 https://www.cve.org/CVERecord?id=CVE-2015-1202 [ 12 ] CVE-2015-1203 https://www.cve.org/CVERecord?id=CVE-2015-1203 [ 13 ] CVE-2015-5949 https://www.cve.org/CVERecord?id=CVE-2015-5949 [ 14 ] CVE-2015-5949 https://www.cve.org/CVERecord?id=CVE-2015-5949 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/201603-08 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to
Get the latest Linux and open source security news straight to your inbox.