VLC Player Gets Patched for Two High-Severity Bugs
#1
Quote:Maintainers of the popular open-source VLC media player patched two high-severity bugs Friday. The flaws were an out-of-bound write vulnerability and a stack-buffer-overflow bug. Developers behind the software, VideoLAN, said the patches were two of 33 fixes being pushed out to the media player and part of a new bug bounty program funded by European Commission.
 
“This high number of security issues is due to the sponsoring of a bug bounty program funded by the European Commission, during the Free and Open Source Software Audit (FOSSA) program,” wrote Jean-Baptiste Kempf, president of VideoLAN and open source developer in a post outlining the patches.
 
In January, the EU funded 14 bug bounty programs in hopes of keeping open source projects that EU institutions rely on secure. The program is maintained by the HackerOne bounty program facilitator.

Details are scant on the two high-severity bugs and how they could be exploited. Impacted is VLC 3.0.7 and the EU-FOSSA release of the player, along with code tied to the upcoming 4.0 release of the player.
“We just released VLC 3.0.7, a minor update of VLC branch 3.0.x. This release is a bit special, because it has more security issues fixed than any other version of VLC,” Kempf wrote.

SOURCE: https://threatpost.com/vlc-player-gets-p...gs/145518/
[-] The following 1 user says Thank You to silversurfer for this post:
  • harlan4096
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
Hasleo software (formerly called EasyUE...
Hasleo Backup Suite ...jasonX — 21:06
Hasleo Backup Suite V5.6.2.1
Hasleo Backup Suit...harlan4096 — 17:41
Opera 128.0.5807.52
Hello! New upda...harlan4096 — 17:39
Brave 1.87.192
Release v1.87.192 ...harlan4096 — 17:38
AdGuard for Windows 7.22.5
AdGuard for Window...harlan4096 — 17:37

[-]
Birthdays
Today's Birthdays
avatar (43)slavrProck
avatar (45)Tyesharaike
avatar (49)TomeRerla
Upcoming Birthdays
avatar (44)gapedDow
avatar (38)snorydar
avatar (43)Hectorvot
avatar (51)knowhanPluts
avatar (39)Williamengiz
avatar (46)qaqapeti
avatar (44)battsourIonix
avatar (43)CedricSek
avatar (39)chasRex
avatar (45)walllMIZ
avatar (41)oconyho
avatar (33)uteluxix
avatar (47)piafcflene
avatar (39)Matthewkah
avatar (51)tersfargum
avatar (50)alfreExept
avatar (38)Charlesfibre
avatar (42)napasvem
avatar (44)diploJeoca
avatar (38)francisnj3
avatar (43)artmaGoork
avatar (45)tukraNax
avatar (41)RichardCisee
avatar (40)ebenofit
avatar (38)ykazawu

[-]
Online Staff
There are no staff members currently online.

>