#14533: vlc-3.0.12
-------------------------+-----------------------
 Reporter:  renodr       |       Owner:  renodr
     Type:  enhancement  |      Status:  assigned
 Priority:  high         |   Milestone:  10.1
Component:  BOOK         |     Version:  SVN
 Severity:  normal       |  Resolution:
 Keywords:               |
-------------------------+-----------------------
Changes (by renodr):

 * priority:  normal => high


Comment:

 As ken noted here originally:

 {{{
 Security Bulletin VLC 3.0.12

 Summary           : Multiple vulnerabilities fixed in VLC media player
 Date              : December 2020
 Affected versions : VLC media player 3.0.11 and earlier
 ID                : VideoLAN-SB-VLC-3012

 Details

 A remote user could create a specifically crafted file that could trigger
 some various issues, notably 2 read buffer overflows, and some invalid
 pointers being dereferenced.
 Impact

 If successful, a malicious third party could trigger either a crash of VLC
 or an arbitratry code execution with the privileges of the target user.

 While these issues in themselves are most likely to just crash the player,
 we can't exclude that they could be combined to leak user informations or
 remotely execute code. ASLR and DEP help reduce the likelyness of code
 execution, but may be bypassed.

 We have not seen exploits performing code execution through these
 vulnerability

 Threat mitigation

 Exploitation of those issues requires the user to explicitly open a
 specially crafted file or stream.
 Workarounds

 The user should refrain from opening files from untrusted third parties or
 accessing untrusted remote sites (or disable the VLC browser plugins),
 until the patch is applied.
 Solution

 VLC media player 3.0.12 addresses the issue.
 Credits

 All but one of the issues fixed in this version have been reported by Zhen
 Zhou, NSFOCUS Security Team
 References

 The VideoLAN project
     http://www.videolan.org/
 VLC official GIT repository
     http://git.videolan.org/?p=vlc.git
 }}}

 And the actual changelog:

 {{{
 Changes between 3.0.12 and 3.0.12.1:
 ----------------------------------

 macOS:
  * 3.0.12.1 is the first release for Apple Silicon macs
  * Version bump to allow an automatic upgrade path

 Changes between 3.0.11.1 and 3.0.12:
 ----------------------------------

 Access:
  * Add new RIST access module compliant with simple profile (VSF_TR-06-1)

 Access Output:
  * Add new RIST access output module compliant with simple profile
 (VSF_TR-06-1)

 Demux:
  * Fixed adaptive's handling of resolution settings
  * Improve Bluray tracks support
  * Improve WMV seeking and DASH support
  * Fix crashes in AVI, MKV modules

 Audio output:
  * Fix audio distortion on macOS during start of playback

 Video Output:
  * Direct3D11: Fix some potential crashes when using video filters

 macOS:
  * Add native support for Apple Silicon / ARM-64
  * Visual UI adaptations for macOS Big Sur
  * Fix displaying EQ bands in the UI depending on which frequency
    presets are set for the EQ in advanced preferences
  * Fix UI issues in bookmarks window

 Misc:
  * Several fixes in the web interface, including privacy and security
    improvements
  * Update YouTube and Vocaroo scripts
  * Fix rotation filter mouse handling
  * Update translations
 }}}

--
Ticket URL: <http://wiki.linuxfromscratch.org/blfs/ticket/14533#comment:4>
BLFS Trac <http://wiki.linuxfromscratch.org/blfs>
Beyond Linux From Scratch
-- 
http://lists.linuxfromscratch.org/listinfo/blfs-book
FAQ: http://www.linuxfromscratch.org/blfs/faq.html
Unsubscribe: See the above information page

Reply via email to