内容简介:A remote user could create a specifically crafted file that could trigger a buffer overflow in VLC's H26X packetizerIf successful, a malicious third party could trigger either a crash of VLC or an arbitratry code execution with the privileges of the target
Summary : Multiple vulnerabilities fixed in VLC media player Date : June 2020 Affected versions : VLC media player 3.0.10 and earlier ID : VideoLAN-SB-VLC-3011 CVE references : CVE-2020-13428
Details
A remote user could create a specifically crafted file that could trigger a buffer overflow in VLC's H26X packetizer
Impact
If successful, a malicious third party could trigger either a crash of VLC or an arbitratry code execution with the privileges of the target user.
While these issues in themselves are most likely to just crash the player, we can't exclude that they could be combined to leak user informations or remotely execute code. ASLR and DEP help reduce the likelyness of code execution, but may be bypassed.
We have not seen exploits performing code execution through these vulnerability
Threat mitigation
Exploitation of those issues requires the user to explicitly open a specially crafted file or stream.
Workarounds
The user should refrain from opening files from untrusted third parties or accessing untrusted remote sites (or disable the VLC browser plugins), until the patch is applied.
Solution
VLC media player 3.0.11 addresses the issue.
Credits
CVE-2020-13428 was reported by Tommy Muir
Additional notes
VLC 3.0.11 also bumps some dependencies, notably libarchive, following the publication of CVE-2020-9308 and CVE-2019-19221
References
- The VideoLAN project
- http://www.videolan.org/
- VLC official GIT repository
- http://git.videolan.org/?p=vlc.git
以上所述就是小编给大家介绍的《Security Bulletin VLC 3.0.11》,希望对大家有所帮助,如果大家有任何疑问请给我留言,小编会及时回复大家的。在此也非常感谢大家对 码农网 的支持!
猜你喜欢:本站部分资源来源于网络,本站转载出于传递更多信息之目的,版权归原作者或者来源机构所有,如转载稿涉及版权问题,请联系我们。
测出转化率:营销优化的科学与艺术
【美】高尔德(Goward,C.) / 谭磊、唐捷译 / 电子工业出版社 / 2014-10-1 / 68.00元
本书作者通过已成功实现大幅提升转化率的案例,展示了大量以营销为核心的电子商务网站的测试设计方法及转化优化方案。书中作者强调了测试及优化思维的重要性,并就实现方法做了详细讲解。 通过本书,读者将学到如何能够在网站遇到发展和收入瓶颈时,测试出存在的问题并找到解决方案;如何可以深入地了解客户需求,并以此为基础优化网站,使其达到提升转化率的目的;如何提升网站的竞争优势,把在线营销渠道变成高效的转化通......一起来看看 《测出转化率:营销优化的科学与艺术》 这本书的介绍吧!