Multiple remotely exploitable denial of service (DoS) and code execution vulnerabilities have been found in the VLC multimedia player and streamer. These bugs have been classified as “high-severity” by the National Vulnerability Database due to their high confidentiality, integrity and availability impact. . These flaws could result in crashes leading to denial of service and Remote Code Execution in Linux. Important updates for VLC that mitigate these issues have been released. We urge all impacted users to apply the VLC updates issued by their distro(s) immediately to prevent attacks leading to downtime and compromise. To stay on top of important updates released by the open-source programs and applications you use, be sure to register as a LinuxSecurity user , then subscribe to our Linux Advisory Watch newsletter and customize your advisories for the distro(s) you use. This will enable you to stay up-to-date on the latest, most significant issues impacting the security of your systems. Follow @LS_Advisories on Twitter for real-time updates on advisories for your distro(s) . . Serious security flaws found in VLC might lead to system crashes and allow remote code execution; users are urged to perform updates.. VLC Security Flaws, Remote Code Execution, Denial of Service, Open Source Software, Multimedia Player. . Brittany Day
The VideoLAN project has announced the release of version 1.1.10 of its VLC media player, the free open source cross-platform multimedia player which supports a variety of audio and video formats. According to the developers, the eleventh release of the 1.1.x branch of VLC is a maintenance and security update that addresses several issues found in the previous update from mid-April.. VLC 1.1.10 fixes several previously reported vulnerabilities in libmodplug, also known as the ModPlug XMMS Plugin, and addresses an integer overflow in the XSPF playlist demultiplexer. Other changes include the removal of FontCache building in the Freetype module, a rewrite of PulseAudio output on Linux/BSD, and various codec and translation updates. A number of Mac OS X interface and hotkey fixes have also been implemented. The link for this article located at H Security is no longer available. . VLC 1.1.10 addresses several security flaws, notably an integer overflow defect in libmodplug, improving overall software safety.. VLC Media Player, Integer Overflow, Multimedia Player Security. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.