VLC Media Player Plagued By Unpatched Critical RCE Flaw
#1
Quote:The VLC open-source media player has a critical-severity bug that could enable remote code execution and other malicious actions. Worse, there is no patch to patch the vulnerability.
 
The VLC media player, developed by the VideoLAN project, is used by more than 3.1 billion users. The vulnerability (CVE-2019-13615) exists in the Windows, Linux and UNIX versions of VLC 3.0.7.1 (the latest version of the media player).
 
“A remote, anonymous attacker can exploit a vulnerability in VLC to execute arbitrary code, create a denial of service state, disclose information, or manipulate files,” according to a release by German security agency CERT-Bund posted over the weekend.  CERT-Bund discovered the vulnerability.
 
According to NIST, the bug ranks 9.8 out of 10 on the CVSS 3.0 scale, making it critical severity. Despite the level of severity, no patch is currently available for the vulnerability. VideoLAN did not respond to a request for comment from Threatpost.
 
According to VideoLAN, current work is being done to create a patch, which is about 60 percent complete. That said, no exploitation of the vulnerability has been observed yet, according to CERT-Bund.

SOURCE: https://threatpost.com/vlc-media-player-...aw/146611/
[-] The following 3 users say Thank You to silversurfer for this post:
  • harlan4096, ismail, Toligo
Reply
#2
Keep Calm, Carry On. VLC Not Affected by Critical Vulnerability!
Quote:A recent security alert caused a panic where people thought the VLC Media Player was affected by a critical vulnerability that had no patch. The problem is that the vulnerability was not in VLC, but rather a module that was replaced over 16 months ago.

Continue reading here: https://www.bleepingcomputer.com/news/se...erability/
[-] The following 1 user says Thank You to silversurfer for this post:
  • harlan4096
Reply


Forum Jump:


Users browsing this thread: 3 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
Sumatra PDF 3.6.1
Changes in 3.6.1: ...harlan4096 — 06:50
Microsoft Edge 146.0.3856.109
Version 146.0.3856...harlan4096 — 06:49
Ventoy 1.1.11
Ventoy 1.1.11 2...harlan4096 — 06:48
uBOLite 2026.405.2010 (already available...
uBOLite 2026.405.2...harlan4096 — 06:47
Android Security Bulletin—April 2026
Android Security B...harlan4096 — 06:46

[-]
Birthdays
Today's Birthdays
avatar (47)creatralGuelm
avatar (38)procnipsut
avatar (44)accenwibly
avatar (41)ahyvily
Upcoming Birthdays
avatar (45)wapedDow
avatar (49)oapedDow
avatar (42)Sanchowogy
avatar (46)MeighGoask
avatar (38)urumahiz
avatar (44)techlignub
avatar (43)Stevenmam
avatar (50)onlinbah
avatar (50)fuspeukChark
avatar (44)werriewWaiNg
avatar (38)Freemanleo
avatar (43)cdoubapKit
avatar (38)lystraPonia
avatar (31)smith8395john
avatar (51)steakelask
avatar (45)Termoplenka
avatar (43)bycoPaist
avatar (49)pieloKat
avatar (43)ilyagNeexy
avatar (51)donitascene
avatar (51)burntLaw
avatar (41)MrDoorsskibheeds
avatar (51)Toligo
avatar (46)Rodneykak
avatar (49)tradeSmode
avatar (39)vemedProkbior
avatar (38)RobertUtelt
avatar (36)Kiran78

[-]
Online Staff
harlan4096's profile harlan4096
Administrator

>