UbuntuUpdates.org

Package "vlc"

Name: vlc

Description:

multimedia player and streamer

Latest version: 3.0.18-4ubuntu0.1
Release: mantic (23.10)
Level: updates
Repository: universe
Homepage: https://www.videolan.org/vlc/

Links


Download "vlc"


Other versions of "vlc" in Mantic

Repository Area Version
base universe 3.0.18-4
security universe 3.0.18-4ubuntu0.1

Packages in group

Deleted packages are displayed in grey.


Changelog

Version: 3.0.18-4ubuntu0.1 2024-05-22 20:07:04 UTC

  vlc (3.0.18-4ubuntu0.1) mantic-security; urgency=medium

  * SECURITY UPDATE: heap buffer overflow and integer underflow
    - debian/patches/CVE-2023-47359-47360.patch: check user size bounds
    - CVE-2023-47359
  * SECURITY UPDATE: integer underflow
    - debian/patches/CVE-2023-47359-47360.patch: check user size bounds
    - CVE-2023-47360

 -- Allen Huang <email address hidden> Mon, 20 May 2024 16:42:33 +0100

CVE-2023-47359 Videolan VLC prior to version 3.0.20 contains an incorrect offset read that leads to a Heap-Based Buffer Overflow in function GetPacket() and results
CVE-2023-47360 Videolan VLC prior to version 3.0.20 contains an Integer underflow that leads to an incorrect packet length.



About   -   Send Feedback to @ubuntu_updates