Updated vlc packages fix security vulnerabilities
Publication date: 27 Aug 2015Modification date: 27 Aug 2015
Type: security
Affected Mageia releases : 4
CVE: CVE-2015-5949
Description
Loren Maggiore of Trail of Bits discovered that the 3GP parser of VLC, a multimedia player and streamer, could dereference an arbitrary pointer due to insufficient restrictions on a writable buffer. This could allow remote attackers to execute arbitrary code via crafted 3GP files (CVE-2015-5949).
References
SRPMS
4/tainted
- vlc-2.1.6-1.1.mga4.tainted
4/core
- vlc-2.1.6-1.1.mga4