Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2021:0691-1

Опубликовано: 08 мая 2021
Источник: suse-cvrf

Описание

Security update for vlc

This update for vlc fixes the following issues:

Update to version 3.0.13:

  • Demux:

    • Adaptive: fix artefacts in HLS streams with wrong profiles/levels
    • Fix regression on some MP4 files for the audio track
    • Fix MPGA and ADTS probing in TS files
    • Fix Flac inside AVI files
    • Fix VP9/Webm artefacts when seeking
  • Codec:

    • Support SSA text scaling
    • Fix rotation on Android rotation
    • Fix WebVTT subtitles that start at 00:00
  • Access:

    • Update libnfs to support NFSv4
    • Improve SMB2 integration
    • Fix Blu-ray files using Unicode names on Windows
    • Disable mcast lookups on Android for RTSP playback
  • Video Output: Rework the D3D11 rendering wait, to fix choppiness on display

  • Interfaces:

    • Fix VLC getting stuck on close on X11 (#21875)
    • Improve RTL on preferences on macOS
    • Add mousewheel horizontal axis control
    • Fix crash on exit on macOS
    • Fix sizing of the fullscreen controls on macOS
  • Misc:

    • Improve MIDI fonts search on Linux
    • Update Soundcloud, Youtube, liveleak
    • Fix compilation with GCC11
    • Fix input-slave option for subtitles
  • Updated translations.

Update to version 3.0.12:

  • Access: Add new RIST access module compliant with simple profile (VSF_TR-06-1).

  • Access Output: Add new RIST access output module compliant with simple profile (VSF_TR-06-1).

  • Demux: Fixed adaptive's handling of resolution settings.

  • Audio output: Fix audio distortion on macOS during start of playback.

  • Video Output: Direct3D11: Fix some potential crashes when using video filters.

  • Misc:

    • Several fixes in the web interface, including privacy and security improvements
    • Update YouTube and Vocaroo scripts.
  • Updated translations.

Список пакетов

openSUSE Leap 15.2
libvlc5-3.0.13-lp152.2.12.1
libvlccore9-3.0.13-lp152.2.12.1
vlc-3.0.13-lp152.2.12.1
vlc-codec-gstreamer-3.0.13-lp152.2.12.1
vlc-devel-3.0.13-lp152.2.12.1
vlc-jack-3.0.13-lp152.2.12.1
vlc-lang-3.0.13-lp152.2.12.1
vlc-noX-3.0.13-lp152.2.12.1
vlc-opencv-3.0.13-lp152.2.12.1
vlc-qt-3.0.13-lp152.2.12.1
vlc-vdpau-3.0.13-lp152.2.12.1

Описание

A vulnerability in EbmlTypeDispatcher::send in VideoLAN VLC media player 3.0.11 allows attackers to trigger a heap-based buffer overflow via a crafted .mkv file.


Затронутые продукты
openSUSE Leap 15.2:libvlc5-3.0.13-lp152.2.12.1
openSUSE Leap 15.2:libvlccore9-3.0.13-lp152.2.12.1
openSUSE Leap 15.2:vlc-3.0.13-lp152.2.12.1
openSUSE Leap 15.2:vlc-codec-gstreamer-3.0.13-lp152.2.12.1

Ссылки