[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

[SECURITY] [DSA 4203-1] vlc security update



-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

- -------------------------------------------------------------------------
Debian Security Advisory DSA-4203-1                   security@debian.org
https://www.debian.org/security/                       Moritz Muehlenhoff
May 17, 2018                          https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package        : vlc
CVE ID         : CVE-2017-17670

Hans Jerry Illikainen discovered a type conversion vulnerability in the
MP4 demuxer of the VLC media player, which could result in the execution
of arbitrary code if a malformed media file is played.

This update upgrades VLC in stretch to the new 3.x release series (as
security fixes couldn't be sensibly backported to the 2.x series). In
addition two packages needed to be rebuild to ensure compatibility with
VLC 3; phonon-backend-vlc (0.9.0-2+deb9u1) and goldencheetah
(4.0.0~DEV1607-2+deb9u1).

VLC in jessie cannot be migrated to version 3 due to incompatible
library changes with reverse dependencies and is thus now declared
end-of-life for jessie. We recommend to upgrade to stretch or pick a
different media player if that's not an option.

For the stable distribution (stretch), this problem has been fixed in
version 3.0.2-0+deb9u1.

We recommend that you upgrade your vlc packages.

For the detailed security status of vlc please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/vlc

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/

Mailing list: debian-security-announce@lists.debian.org
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEtuYvPRKsOElcDakFEMKTtsN8TjYFAlr9nlUACgkQEMKTtsN8
Tjb5rw/+OncZS6nB0uDqmA0RcZugqvskqQReQbBqImwSSEzn2u9JY6wgi/Rmiuvr
N+wsrXTw9ws2yewMah9Yy+K0+Ucq0+Hl+pPtjaSFhC8RKaYXZaS3GsdxutWuLxgz
WtRPIU3o4+PP8fssR9P7uHRYESmT2+sccIB55vBj9TvLzZhgQJz4sniowbJ7en96
lVTBFpBesXXmijbLcabLSOzGDQ5qVcN5P4f+Alng+D5b1buIw75Efw70S9HCYX8H
YexCfzOxEqcBxV3UNaUWPSXD/OCXt8cGxLzuQa03YhgDJLlasuXYJifPq8bffBkB
UhE9yhDs9eZFyUMgZZ7dQVl6fO1/qKYBW4nTNAc2MTyPL+8olO2fSdA4nG4hDR8i
HJC8E+vyWrbzYIivDEuDQats6e24R1wXrCdo1TG11R6iY7t1Mqg7paufK2oOOWbr
XRF6rkpWhlfo3EJoU2dqxs90/LHnPaAM89GPkNBftmDrBKYKw3QhiULp2t6Ob9rk
FTkycbZrGFKDTeacLfCZ6JnqrKHQC8F0M5JvV19ff1NU6SvpRWHxPQC3C/22u1L0
rjWPE0nLimyQ2QnHn8/hNp6sK0iEAGrl+XLPrw+dewsObq+UCDgHuyHJfYJnX2hx
IGvl7VddHx5kBD78rL1ODMVmWIRHavt193u7/jfUKT+2PxOUwnY=
=a0n7
-----END PGP SIGNATURE-----


Reply to: