Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2022:10252-1

Опубликовано: 27 дек. 2022
Источник: suse-cvrf

Описание

Security update for vlc

This update for vlc fixes the following issues:

  • Update to version 3.0.18 (CVE-2022-41325, boo#1206142):
    • macOS: Fix audio device listing with non-latin names.
    • Misc: Fix rendering and performance issue with older GPUs.
    • Updated translations.
  • Changes from version 3.0.18-rc2:
    • Codec/Demux:
      • Add support for Y16 chroma.
      • Fix build of gme plugin.
    • Lua:
      • Fix script for vocaroo.
      • Fix script for youtube to allow throttled playback.
    • Service Discovery: Fix UPnP regression on Windows.
    • Video Output: Fix video placement with caopengllayer.
    • Misc: Fix password search in kwallet module.
  • Changes from version 3.0.18-rc:
    • Demux:
      • Major adaptive streaming update, notably for multiple timelies and webvtt.
      • Fix seeking with some fragmented MP4 files.
      • Add support for DVBSub inside MKV.
      • Fix some Flac files that could not be played.
      • Improve seeking in Ogg files.
    • Decoders:
      • Fix DxVA/D3D11 crashes on HEVC files with bogus references.
      • Fix libass storage size and crash.
      • Fix decoding errors on macOS hw decoding on some HEVC files.
    • Video Output:
      • Fix color regression with VAAPI/iOS and OpenGL output.
      • Fix some resizing issues with OpenGL on GLX/EGL/X11/XV.
      • Fix Direct3d9 texture stretching.
      • Fix 10-bit accelerated video filters on macOS.
    • Playlist: Avoid playlist liveloop on failed/tiny items (temporize EOS bursts).
    • Misc:
      • Misc fixes for the extension UI on macOS.
      • Improve SMBv1 and SMBv2 behaviours.
      • Improve FTP compatibility.
      • Support RISC-V.
      • Fix AVI muxing for Windows Media Player compatibility.
      • Fix seeking speed on macOS.

Список пакетов

SUSE Package Hub 15 SP3
libvlc5-3.0.18-bp153.2.6.1
libvlccore9-3.0.18-bp153.2.6.1
vlc-3.0.18-bp153.2.6.1
vlc-codec-gstreamer-3.0.18-bp153.2.6.1
vlc-devel-3.0.18-bp153.2.6.1
vlc-jack-3.0.18-bp153.2.6.1
vlc-lang-3.0.18-bp153.2.6.1
vlc-noX-3.0.18-bp153.2.6.1
vlc-opencv-3.0.18-bp153.2.6.1
vlc-qt-3.0.18-bp153.2.6.1
vlc-vdpau-3.0.18-bp153.2.6.1
openSUSE Leap 15.3
libvlc5-3.0.18-bp153.2.6.1
libvlccore9-3.0.18-bp153.2.6.1
vlc-3.0.18-bp153.2.6.1
vlc-codec-gstreamer-3.0.18-bp153.2.6.1
vlc-devel-3.0.18-bp153.2.6.1
vlc-jack-3.0.18-bp153.2.6.1
vlc-lang-3.0.18-bp153.2.6.1
vlc-noX-3.0.18-bp153.2.6.1
vlc-opencv-3.0.18-bp153.2.6.1
vlc-qt-3.0.18-bp153.2.6.1
vlc-vdpau-3.0.18-bp153.2.6.1

Описание

In FLAC__bitreader_read_rice_signed_block of bitreader.c, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-156076070


Затронутые продукты
SUSE Package Hub 15 SP3:libvlc5-3.0.18-bp153.2.6.1
SUSE Package Hub 15 SP3:libvlccore9-3.0.18-bp153.2.6.1
SUSE Package Hub 15 SP3:vlc-3.0.18-bp153.2.6.1
SUSE Package Hub 15 SP3:vlc-codec-gstreamer-3.0.18-bp153.2.6.1

Ссылки

Описание

In append_to_verify_fifo_interleaved_ of stream_encoder.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-174302683


Затронутые продукты
SUSE Package Hub 15 SP3:libvlc5-3.0.18-bp153.2.6.1
SUSE Package Hub 15 SP3:libvlccore9-3.0.18-bp153.2.6.1
SUSE Package Hub 15 SP3:vlc-3.0.18-bp153.2.6.1
SUSE Package Hub 15 SP3:vlc-codec-gstreamer-3.0.18-bp153.2.6.1

Ссылки

Описание

An integer overflow in the VNC module in VideoLAN VLC Media Player through 3.0.17.4 allows attackers, by tricking a user into opening a crafted playlist or connecting to a rogue VNC server, to crash VLC or execute code under some conditions.


Затронутые продукты
SUSE Package Hub 15 SP3:libvlc5-3.0.18-bp153.2.6.1
SUSE Package Hub 15 SP3:libvlccore9-3.0.18-bp153.2.6.1
SUSE Package Hub 15 SP3:vlc-3.0.18-bp153.2.6.1
SUSE Package Hub 15 SP3:vlc-codec-gstreamer-3.0.18-bp153.2.6.1

Ссылки
Уязвимость openSUSE-SU-2022:10252-1