Stories
Slash Boxes
Comments

SoylentNews is people

SoylentNews is powered by your submissions, so send in your scoop. Only 17 submissions in the queue.
posted by Fnord666 on Thursday August 22 2019, @03:23AM   Printer-friendly
from the like-The-Ring dept.

Stuff like sophisticated government spyware is scary and all – but don't forget, a single .wmv file can pwn you via VLC:

VideoLAN has issued an update to address a baker's dozen of CVE-listed security vulnerabilities in its widely used VLC player software.

The VLC update includes patches to clear up flaws that range in impact from denial of service (read: application crashes) to remote code execution (i.e. malware installation). Users and admins can get fixes for all of the vulnerabilities by updating VLC to version 3.0.8 or later.

So far, no attacks exploiting these holes have been reported in the wild.

"While these issues in themselves are most likely to just crash the player, we can't exclude that they could be combined to leak user information or remotely execute code," VideoLAN offered in announcing the update. "ASLR and DEP help reduce the likeliness of code execution, but may be bypassed."

Each of the 13 flaws would be exploited by opening a booby-trapped media file, such as vids in WMV, MP4, AVI, and OGG formats. In other cases, the flaws could be exploited via browser plugins by visiting a malicious webpage.

Get updated version 3.0.8 from the VLC Download Page.


Original Submission

 
This discussion has been archived. No new comments can be posted.
Display Options Threshold/Breakthrough Mark All as Read Mark All as Unread
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
  • (Score: 0) by Anonymous Coward on Thursday August 22 2019, @03:51PM

    by Anonymous Coward on Thursday August 22 2019, @03:51PM (#883684)

    A couple of modifications to the vlc.Slackbuild from alien, a download of the sources..run the script, go away for while, voila, one Slackware laptop running 3.0.8 (a priority, as it's the laptop that normally gets used to play random.video.files.from.torrents).

    I'll copy the package over to the local server here and the desktop machines will update their copies from there, that is, unless the alien version gets updated first.