VLC Media Player GnuTLS and Libxml2 Vulnerabilities

ERCOLINO

Membro dello Staff
Amministratore
Registrato
3 Marzo 2003
Messaggi
255.907
Località
Torino
Secunia Advisory: SA30560
Release Date: 2008-06-09

Critical: Moderately critical
Impact: DoS
System access
Where: From remote
Solution Status: Vendor Patch

Software: VLC media player 0.x

CVE reference:
CVE-2008-1948 (Secunia mirror)
CVE-2008-1949 (Secunia mirror)
CVE-2008-1950 (Secunia mirror)
CVE-2007-6284 (Secunia mirror)



Description:
Some vulnerabilities have been reported in VLC Media Player, which potentially can be exploited by malicious people to cause a DoS (Denial of Service) or compromise a user's system.

The vulnerabilities are caused due to the inclusion of vulnerable GnuTLS and Libxml2 libraries in Windows and Mac OS X packages.

For more information:
SA28444
SA30287

The vulnerabilities are reported in versions prior to 0.8.6h.


Solution:
Update to version 0.8.6h.



Bollettino Sicurezza
 
Indietro
Alto Basso