MGASA-2019-0233

Source
https://advisories.mageia.org/MGASA-2019-0233.html
Import Source
https://advisories.mageia.org/MGASA-2019-0233.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2019-0233
Related
Published
2019-08-31T13:22:36Z
Modified
2019-08-31T12:31:45Z
Summary
Updated vlc packages fixes security vulnerabilities
Details

Updated vlc packages fixes security vulnerabilities:

Multiple security issues were discovered in the VLC media player, which could result in the execution of arbitrary code or denial of service if a malformed file/stream is processed (CVE-2019-13602, CVE-2019-13962, CVE-2019-14437, CVE-2019-14438, CVE-2019-14498, CVE-2019-14533, CVE-2019-14534, CVE-2019-14535, CVE-2019-14776, CVE-2019-14777, CVE-2019-14778, CVE-2019-14970).

The vlc package has been updated to version 3.0.8, fixing these issues and other bugs. In Mageia 6, the libebml package has been updated to version 1.3.7, which is needed for Matroska support.

References
Credits

Affected packages

Mageia:7 / vlc

Package

Name
vlc
Purl
pkg:rpm/mageia/vlc?distro=mageia-7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.0.8-1.mga7.tainted

Ecosystem specific

{
    "section": "tainted"
}

Mageia:7 / vlc

Package

Name
vlc
Purl
pkg:rpm/mageia/vlc?distro=mageia-7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.0.8-1.mga7

Ecosystem specific

{
    "section": "core"
}

Mageia:6 / vlc

Package

Name
vlc
Purl
pkg:rpm/mageia/vlc?distro=mageia-6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.0.8-1.mga6.tainted

Ecosystem specific

{
    "section": "tainted"
}

Mageia:6 / vlc

Package

Name
vlc
Purl
pkg:rpm/mageia/vlc?distro=mageia-6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.0.8-1.mga6

Ecosystem specific

{
    "section": "core"
}

Mageia:6 / libebml

Package

Name
libebml
Purl
pkg:rpm/mageia/libebml?distro=mageia-6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.3.7-1.mga6

Ecosystem specific

{
    "section": "core"
}