giovedì 02 maggio 2024 13:53mobile    |    3dfxzone.it    |    amdzone.it    |    atizone.it    |    forumzone.it    |    hwsetup.it    |    nvidiazone.it    |    unixzone.it 
NVIDIAZONE.IT
              proudly powered by 3dfxzone.it
Home    |    News    |    Headlines    |    Articoli    |    Download    |    Community    |    Condividi    |    Contatti    |    Tag    |    Ricerca    |    Sitemap
 
Pubblicità Informazioni e Release Notes del file: VLC Media Player 3.0.7 Ultime News
Condividi su Facebook Condividi su Twitter Condividi su WhatsApp Condividi su reddit

We just released VLC 3.0.7, a minor update of VLC branch 3.0.x. This release is a bit special, because it has more security issues fixed than any other version of VLC.

This high number of security issues is due to the sponsoring of a bug bounty program funded by the European Commission, during the FOSSA program.

Severity

According to our scale, we have had 33 valid security issues fixed thanks to this program:

  • 2 high security issues, (only one was present in 3.0.x),
  • 21 medium security issues,
  • 20 low security issues.

The 2 more important issues are an Out-of-Bound Write and a Stack Buffer Overflow.

the Out-of-Bound Write is not in the VLC codebase, but in a dependency of VLC, the faad2 library, unmaintained, unfortunately.

the Stack Buffer Overflow is a VLC 4.0-only issue in the new RIST module, and is therefore not impacting actual release of VLC.

The medium security issues are mostly out-of-band reads, heap overflows, NULL-dereference and use-after-free security issues. Those issues should not be exploitable with ASLR, but are important anyway, because they can crash VLC.

The low security issues are mostly integer overflow, division by zero, and other out-of-band reads with no actual impact. Those issues are not exploitable.

02.05.2024  
System Information & Windows Tools: USB Device Tree Viewer 4.2.3 - Bug fixing
01.05.2024  
YouTube Gameplay: Painkiller | Havok Physics Engine | Gameplay Footage #2
Philips introduce il gaming monitor Evnia 49M2C8900 con pannello OLED QD curvo
ASUS annuncia la data di lancio dei suoi notebook con SoC Qualcomm Snapdragon X
NVIDIA rilascia il package Linux x64 (AMD64/EM64T) Display Driver 550.78
MiTeC System Information X 5.0.0 visualizza le specifiche hardware del PC
FastCopy 5.7.7 copia file e directory, e sincronizza in modalità incrementale
Privacy Eraser 6.6.3 protegge la privacy degli utenti di Microsoft Windows
30.04.2024  
Personal Backup 6.3.15.1 crea backup di file e dati anche in formato compresso
HDD & SSD - Monitoring & Information Utilities: CrystalDiskInfo 9.3.0 [Portable]
29.04.2024  
Le GeForce RTX 4070 con GPU AD103 esistono e la conferma arriva da GPU-Z
Free Antivirus & Antimalware Utilities: Trellix Stinger 13.0.0.110 [Portable]
GPU & Vulkan APIs | Information Tools: Vulkan Hardware Capability Viewer 3.40
System & Hardware Tools: SIW (System Information for Windows) 2024 14.1.0417a
28.04.2024  
Internet Utilities: Free Download Manager 6.22 - HTTPS, FTP, Bittorrent Ready
The Linux Kernel Organization rilascia il Linux Kernel 6.8.8: info e download
27.04.2024  
Onda introduce la video card Radeon RX 6600 LE AEGIS (non annunciata da AMD)
Con l'app free FileZilla Server 1.8.2 puoi creare il tuo server FTP a costo zero
AMD rilascia Radeon Software for Linux 23.40.2 - Radeon RX 7900 GRE Ready
GeForce & Radeon - Tuning & Monitoring Tools: ASUS GPU Tweak III 1.7.7.0
Indice delle news 
Ultimi File
Painkiller | Havok Physics Engine | Gameplay Footage #2
NVIDIA Linux X64 (AMD64/EM64T) Display Driver 550.78
MiTeC System Information X 5.0.0
Vulkan Hardware Capability Viewer 3.40
SIW (System Information for Windows) 2024 14.1.0417a
ASUS GPU Tweak III 1.7.7.0
Prime95 30.19 build 14 - Mac OS X
Prime95 30.19 build 14 - FreeBSD 64-bit
Prime95 30.19 build 14 - Linux 64-bit
Prime95 30.19 build 14 - Linux 32-bit
Indice dei file 
3dfxzone.it   ][   amdzone.it   ][   atizone.it   ][   forumzone.it   ][   hwsetup.it   ][   nvidiazone.it   ][   unixzone.it   ][   links   ][   feed rss   ][   chi siamo   ][   sitemap
NVIDIAZONE.IT è servito da una applicazione proprietaria di cui è vietata la replicazione parziale o totale (layout e/o logica). I marchi e le sigle in esso citate sono proprietà degli aventi diritto. Note Legali. Privacy.