openSUSE-SU-2019:1897-1
Dashboard / Vulnerabilities / openSUSE-SU-2019:1897-1
openSUSE-SU-2019:1897-1
Summary: Security update for vlc
Details: This update for vlc to version 3.0.7.1 fixes the following issues: Security issues fixed: - CVE-2019-5439: Fixed a buffer overflow (bsc#1138354). - CVE-2019-5459: Fixed an integer underflow (bsc#1143549). - CVE-2019-5460: Fixed a double free (bsc#1143547). - CVE-2019-12874: Fixed a double free in zlib_decompress_extra in modules/demux/mkv/util.cpp (bsc#1138933). - CVE-2019-13602: Fixed an integer underflow in mp4 demuxer (boo#1141522). - CVE-2019-13962: Fixed a heap-based buffer over-read in avcodec (boo#1142161). Non-security issues fixed: - Video Output: * Fix hardware acceleration with some AMD drivers * Improve direct3d11 HDR support - Access: * Improve Blu-ray support - Audio output: * Fix pass-through on Android-23 * Fix DirectSound drain - Demux: Improve MP4 support - Video Output: * Fix 12 bits sources playback with Direct3D11 * Fix crash on iOS * Fix midstream aspect-ratio changes when Windows hardware decoding is on * Fix HLG display with Direct3D11 - Stream Output: Improve Chromecast support with new ChromeCast apps - Misc: * Update Youtube, Dailymotion, Vimeo, Soundcloud scripts * Work around busy looping when playing an invalid item with loop enabled - Updated translations. This update was imported from the openSUSE:Leap:15.1:Update update project.
References: https://lists.opensuse.org/archives/list/[email protected]/thread/BZ6PVIORM3E3KCDWEJP6ZSJVHTRTXT2M/#BZ6PVIORM3E3KCDWEJP6ZSJVHTRTXT2M, https://bugzilla.suse.com/1118586, https://bugzilla.suse.com/1138354, https://bugzilla.suse.com/1138933, https://bugzilla.suse.com/1141522, https://bugzilla.suse.com/1142161, https://bugzilla.suse.com/1143547, https://bugzilla.suse.com/1143549, https://www.suse.com/security/cve/CVE-2018-19857, https://www.suse.com/security/cve/CVE-2019-12874, https://www.suse.com/security/cve/CVE-2019-13602, https://www.suse.com/security/cve/CVE-2019-13962, https://www.suse.com/security/cve/CVE-2019-5439, https://www.suse.com/security/cve/CVE-2019-5459, https://www.suse.com/security/cve/CVE-2019-5460
Affected packages
Package
Name: vlc
Purl: pkg:rpm/suse/vlc&distro=SUSE%20Package%20Hub%2015%20SP1
Affected ranges
Type: ECOSYSTEM
Events:
