Описание
Security update for vlc
This update for vlc fixes the following issues:
- Update to version 3.0.18 (CVE-2022-41325, boo#1206142):
- macOS: Fix audio device listing with non-latin names.
- Misc: Fix rendering and performance issue with older GPUs.
- Updated translations.
- Changes from version 3.0.18-rc2:
- Codec/Demux:
- Add support for Y16 chroma.
- Fix build of gme plugin.
- Lua:
- Fix script for vocaroo.
- Fix script for youtube to allow throttled playback.
- Service Discovery: Fix UPnP regression on Windows.
- Video Output: Fix video placement with caopengllayer.
- Misc: Fix password search in kwallet module.
- Codec/Demux:
- Changes from version 3.0.18-rc:
- Demux:
- Major adaptive streaming update, notably for multiple timelies and webvtt.
- Fix seeking with some fragmented MP4 files.
- Add support for DVBSub inside MKV.
- Fix some Flac files that could not be played.
- Improve seeking in Ogg files.
- Decoders:
- Fix DxVA/D3D11 crashes on HEVC files with bogus references.
- Fix libass storage size and crash.
- Fix decoding errors on macOS hw decoding on some HEVC files.
- Video Output:
- Fix color regression with VAAPI/iOS and OpenGL output.
- Fix some resizing issues with OpenGL on GLX/EGL/X11/XV.
- Fix Direct3d9 texture stretching.
- Fix 10-bit accelerated video filters on macOS.
- Playlist: Avoid playlist liveloop on failed/tiny items (temporize EOS bursts).
- Misc:
- Misc fixes for the extension UI on macOS.
- Improve SMBv1 and SMBv2 behaviours.
- Improve FTP compatibility.
- Support RISC-V.
- Fix AVI muxing for Windows Media Player compatibility.
- Fix seeking speed on macOS.
- Demux:
Список пакетов
SUSE Package Hub 15 SP3
openSUSE Leap 15.3
Ссылки
- E-Mail link for openSUSE-SU-2022:10252-1
- SUSE Security Ratings
- SUSE Bug 1200944
- SUSE Bug 1206142
- SUSE CVE CVE-2020-0499 page
- SUSE CVE CVE-2021-0561 page
- SUSE CVE CVE-2022-41325 page
Описание
In FLAC__bitreader_read_rice_signed_block of bitreader.c, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-156076070
Затронутые продукты
Ссылки
- CVE-2020-0499
- SUSE Bug 1180099
Описание
In append_to_verify_fifo_interleaved_ of stream_encoder.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-174302683
Затронутые продукты
Ссылки
- CVE-2021-0561
- SUSE Bug 1196660
Описание
An integer overflow in the VNC module in VideoLAN VLC Media Player through 3.0.17.4 allows attackers, by tricking a user into opening a crafted playlist or connecting to a rogue VNC server, to crash VLC or execute code under some conditions.
Затронутые продукты
Ссылки
- CVE-2022-41325
- SUSE Bug 1206142