MGASA-2020-0272

Source
https://advisories.mageia.org/MGASA-2020-0272.html
Import Source
https://advisories.mageia.org/MGASA-2020-0272.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2020-0272
Related
Published
2020-07-04T22:47:21Z
Modified
2020-07-04T22:15:05Z
Summary
Updated vlc packages fix security vulnerability
Details

Updated vlc packages fixes security vulnerability:

A heap-based buffer overflow in the hxxxAnnexBtoxVC function in modules/packetizer/hxxxnal.c in VideoLAN VLC media player before 3.0.11 allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via a crafted H.264 Annex-B video (.avi for example) file (CVE-2020-13428).

The vlc package has been updated to version 3.0.11, fixing this issue and other bugs.

References
Credits

Affected packages

Mageia:7 / vlc

Package

Name
vlc
Purl
pkg:rpm/mageia/vlc?distro=mageia-7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.0.11-1.mga7

Ecosystem specific

{
    "section": "core"
}