venerdì 26 aprile 2024 01:38 mobile  |  3dfxzone.it  |  amdzone.it  |  atizone.it  |  forumzone.it  |  hwsetup.it  |  nvidiazone.it  |  unixzone.it  
AMDZONE.IT
 proudly powered by 3dfxzone.it
Home    |    News    |    Headlines    |    Articoli    |    Download    |    Community    |    Redazione    |    Condividi    |    Tag    |    Ricerca    |    Sitemap
ADV Informazioni e Release Notes del file: VLC Media Player 3.0.7 Ultime News
Condividi su Facebook Condividi su Twitter Condividi su WhatsApp Condividi su reddit

We just released VLC 3.0.7, a minor update of VLC branch 3.0.x. This release is a bit special, because it has more security issues fixed than any other version of VLC.

This high number of security issues is due to the sponsoring of a bug bounty program funded by the European Commission, during the FOSSA program.

Severity

According to our scale, we have had 33 valid security issues fixed thanks to this program:

  • 2 high security issues, (only one was present in 3.0.x),
  • 21 medium security issues,
  • 20 low security issues.

The 2 more important issues are an Out-of-Bound Write and a Stack Buffer Overflow.

the Out-of-Bound Write is not in the VLC codebase, but in a dependency of VLC, the faad2 library, unmaintained, unfortunately.

the Stack Buffer Overflow is a VLC 4.0-only issue in the new RIST module, and is therefore not impacting actual release of VLC.

The medium security issues are mostly out-of-band reads, heap overflows, NULL-dereference and use-after-free security issues. Those issues should not be exploitable with ASLR, but are important anyway, because they can crash VLC.

The low security issues are mostly integer overflow, division by zero, and other out-of-band reads with no actual impact. Those issues are not exploitable.

25.04.2024  
Benchmark & Stability Testing: Prime95 30.19 build 14 - Windows, Linux, BSD, Mac
24.04.2024  
AMD prepara il lancio dei processori AM5 EPYC 4004 per cloud e data center
23.04.2024  
AMD potrebbe utilizzare ancora memoria GDDR6 per le prime Radeon RX 8000
22.04.2024  
Video & GPU - Monitoring & Setup & Tuning Tools: ColorControl 9.9.0.1
Display Driver Uninstaller 18.0.7.6 rimuove i driver GPU di AMD, Intel e NVIDIA
20.04.2024  
Windows Tweaking & Tuning & Security Utilities: Windows 11 Manager 1.4.4
ASUS e MSI confermano il lancio dei processori Ryzen 9000 basati su AMD Zen 5
GPU-Z 2.59.0 supporta le GPU NVIDIA Ada Lovelace RTX 2000 e RTX 1000
19.04.2024  
Hardware Monitoring & Benchmark: AIDA64 Extreme Edition 7.20.6820 beta
Windows Audio & Video & Codecs Tools: DivX Software 11.0.1 - AMD hardware fix
18.04.2024  
Samsung annuncia i primi chip di LPDDR5X con data rate fino a 10.7Gbps
16.04.2024  
Arriva la conferma ufficiosa delle specifiche della PlayStation 5 Pro (Trinity)
15.04.2024  
Video & GPU - Monitoring & Setup & Tuning Tools: ColorControl 9.9.0.0
14.04.2024  
Free PDF Viewing & Printing Tools: Adobe Acrobat Reader DC 2024.002.20687
12.04.2024  
Benchmark & Testing Utilities: Passmark PerformanceTest 11.0 build 1014
Benchmark: Geekbench 6.3.0 - Windows, Mac, Linux, Android, iPhone Ready
GeForce & Radeon - Tuning & Monitoring Tools: ASUS GPU Tweak III 1.7.6.1
11.04.2024  
Display Driver Uninstaller 18.0.7.5 rimuove i driver GPU di AMD, Intel e NVIDIA
10.04.2024  
RegCool 2.000 esegue ricerche, crea backup e modifica il registro di Windows
09.04.2024  
L'app Dragon Center 2.0.146.0 configura, monitora e ottimizza i sistemi MSI
Indice delle news 
Ultimi File
Prime95 30.19 build 14 - Mac OS X
Prime95 30.19 build 14 - FreeBSD 64-bit
Prime95 30.19 build 14 - Linux 64-bit
Prime95 30.19 build 14 - Linux 32-bit
Prime95 30.19 build 14 - Windows 64-bit
Prime95 30.19 build 14 - Windows 32-bit
Windows 10 Manager 3.9.4 [Portable]
Intel Arc & Iris Xe Graphics Driver 31.0.101.5444
Windows 11 Manager 1.4.4 [Portable]
GPU-Z 2.59.0
AIDA64 Extreme Edition 7.20.6820 beta
Adobe Acrobat Reader DC 2024.002.20687
Indice dei file 
A M D Z O N E . I T
3dfxzone.it         |       amdzone.it         |       atizone.it         |       forumzone.it         |       hwsetup.it         |       nvidiazone.it         |       unixzone.it         |       feed rss         |       links
AMDZone.it è servito da una applicazione proprietaria di cui è vietata la riproduzione parziale o totale (layout e/o logica). I marchi e le sigle in esso citate sono proprietà degli aventi diritto. Note legali. Privacy.