USN-4131-1: VLC vulnerabilities
vlc vulnerabilities
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 19.04
- Ubuntu 18.04 LTS
Summary
Several security issues were fixed in VLC.
Software Description
- vlc – multimedia player and streamer
Details
It was discovered that VLC incorrectly handled certain media files. If a
user were tricked into opening a specially-crafted file, a remote attacker
could use this issue to cause VLC to crash, resulting in a denial of
service, or possibly execute arbitrary code.
Update instructions
The problem can be corrected by updating your system to the following package versions:
- Ubuntu 19.04
- vlc – 3.0.8-0ubuntu19.04.1
- Ubuntu 18.04 LTS
- vlc – 3.0.8-0ubuntu18.04.1
To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades.
In general, a standard system update will make all the necessary changes.
References
- CVE-2019-13962
- CVE-2019-14437
- CVE-2019-14438
- CVE-2019-14498
- CVE-2019-14533
- CVE-2019-14534
- CVE-2019-14535
- CVE-2019-14776
- CVE-2019-14777
- CVE-2019-14778
- CVE-2019-14970
Source: USN-4131-1: VLC vulnerabilities