Re: VLC player has a critical flaw – and the re’s no patch yet

Peter Reutemann <[email protected]>
Newsgroups gmane.org.user-groups.linux.waikato
Message-ID <CAHoQ12L0s=uWV+bbeP-9b9j=Bz3_tC-DMHJXzw5oBmsix_Z5rw@mail.gmail.com>
> 'On the flip side, there are currently no known cases of the
> vulnerability being exploited in the wild
>
> Germany’s national Computer Emergency Response Team (CERT-Bund) has
> issued a security advisory to alert users of VLC media player of a
> severe vulnerability affecting this extremely popular open-source
> software.
>
> “A remote, anonymous attacker can exploit the vulnerability in VLC to
> execute arbitrary code, cause a denial-of-service condition,
> exfiltrate information, or manipulate files,” said CERT-Bund, which
> also discovered the security loophole.
>
> The memory-corruption flaw is known to reside in the player’s latest
> release, 3.0.7.1, but may also be present in its earlier versions. It
> affects the program’s Windows, Linux and UNIX versions and has earned
> a score of 4 out of 5 on the German agency’s severity scale.'
>
> -- source: https://cybersafe.mcttrainingconsultant.com/?p=14585

Follow up:
"VLC Developer Debunks Reports of 'Critical Security Issue' In Open
Source Media Player"

-- source: https://linux.slashdot.org/story/19/07/24/2124240

Cheers, Peter
-- 
Peter Reutemann
Dept. of Computer Science
University of Waikato, NZ
+64 (7) 858-5174
http://www.cms.waikato.ac.nz/~fracpete/
http://www.data-mining.co.nz/
_______________________________________________
wlug mailing list | [email protected]
Unsubscribe: https://list.waikato.ac.nz/mailman/listinfo/wlug
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.