MGASA-2018-0400

Source
https://advisories.mageia.org/MGASA-2018-0400.html
Import Source
https://advisories.mageia.org/MGASA-2018-0400.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2018-0400
Related
Published
2018-10-19T18:00:37Z
Modified
2022-02-17T18:21:47Z
Summary
Updated vlc packages fix security vulnerability
Details

This update provides vlc 3.0.4 and fixes at least the following security issue:

A use-after-free was discovered in the MP4 demuxer of the VLC media player, which could result in the execution of arbitrary code if a malformed media file is played (CVE-2018-11529)

For other fixes in this update, see the referenced NEWS.

References
Credits

Affected packages

Mageia:6 / vlc

Package

Name
vlc
Purl
pkg:rpm/mageia/vlc?distro=mageia-6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.0.4-1.mga6

Ecosystem specific

{
    "section": "core"
}

Mageia:6 / vlc

Package

Name
vlc
Purl
pkg:rpm/mageia/vlc?distro=mageia-6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.0.4-1.mga6.tainted

Ecosystem specific

{
    "section": "tainted"
}