venerdì 19 aprile 2024 03:18mobile    |    3dfxzone.it    |    amdzone.it    |    atizone.it    |    forumzone.it    |    hwsetup.it    |    nvidiazone.it    |    unixzone.it 
NVIDIAZONE.IT
              proudly powered by 3dfxzone.it
Home    |    News    |    Headlines    |    Articoli    |    Download    |    Community    |    Condividi    |    Contatti    |    Tag    |    Ricerca    |    Sitemap
 
Pubblicità Informazioni e Release Notes del file: VLC Media Player 3.0.7 Ultime News
Condividi su Facebook Condividi su Twitter Condividi su WhatsApp Condividi su reddit

We just released VLC 3.0.7, a minor update of VLC branch 3.0.x. This release is a bit special, because it has more security issues fixed than any other version of VLC.

This high number of security issues is due to the sponsoring of a bug bounty program funded by the European Commission, during the FOSSA program.

Severity

According to our scale, we have had 33 valid security issues fixed thanks to this program:

  • 2 high security issues, (only one was present in 3.0.x),
  • 21 medium security issues,
  • 20 low security issues.

The 2 more important issues are an Out-of-Bound Write and a Stack Buffer Overflow.

the Out-of-Bound Write is not in the VLC codebase, but in a dependency of VLC, the faad2 library, unmaintained, unfortunately.

the Stack Buffer Overflow is a VLC 4.0-only issue in the new RIST module, and is therefore not impacting actual release of VLC.

The medium security issues are mostly out-of-band reads, heap overflows, NULL-dereference and use-after-free security issues. Those issues should not be exploitable with ASLR, but are important anyway, because they can crash VLC.

The low security issues are mostly integer overflow, division by zero, and other out-of-band reads with no actual impact. Those issues are not exploitable.

18.04.2024  
HFS - HTTP File Server 0.52.1 consente di realizzare un server HTTP a costo zero
Dopo la Arc A750 OC, BIOSTAR annuncia anche la video card Arc A380 ST
Samsung annuncia i primi chip di LPDDR5X con data rate fino a 10.7Gbps
Blender 4.1.1 supporta l'utente nella generazione di contenuti grafici in 3D
L'app MediaInfo 24.04 visualizza le proprietà dei file multimediali ed è free
17.04.2024  
SSD & HDD Storage Drives - Monitoring & Benchmark Utilities: HD Tune Pro 6.00
Oracle rilascia VirtualBox 7.0.16 per Windows, Linux, macOS e Unix Solaris
The Linux Kernel Organization rilascia il Linux Kernel 6.8.7: info e download
16.04.2024  
Incrementa la sicurezza di Windows 11 con Windows Firewall Control 6.9.9.8
Arriva la conferma ufficiosa delle specifiche della PlayStation 5 Pro (Trinity)
SSH/Telnet/Rlogin Client & Console: PuTTY 0.81 - Windows x86 / x64 / ARM
Free Antivirus & Antimalware Utilities: Trellix Stinger 13.0.0.102 [Portable]
15.04.2024  
Video & GPU - Monitoring & Setup & Tuning Tools: ColorControl 9.9.0.0
Wipe 2404 rimuove file e protegge la privacy degli utenti di Microsoft Windows
L'utility Open Source ReShade 6.1.1 può migliorare la resa grafica dei videogame
System Information & Windows Tools: USB Device Tree Viewer 4.2.2
14.04.2024  
NIUBI Partition Editor 9.9.5 gestisce partizioni, volumi e file system dei drive
Free PDF Viewing & Printing Tools: Adobe Acrobat Reader DC 2024.002.20687
13.04.2024  
BIOSTAR diventa partner di Intel Graphics e annuncia la video card Arc A750 OC
Free Audio & Multimedia Windows Players: foobar2000 2.1.4 - Bug fixing
Indice delle news 
Ultimi File
Adobe Acrobat Reader DC 2024.002.20687
Passmark PerformanceTest 11.0 build 1014
Geekbench 6.3.0
ASUS GPU Tweak III 1.7.6.1
RegCool 2.000
MSI Dragon Center 2.0.146.0
7-Zip 24.04 beta
MechWarrior 5: Clans GDC Demo Trailer
GPU Shark 2.2.0.0 [Portable]
FurMark OpenGL Benchmark 2.2.0.1
Indice dei file 
3dfxzone.it   ][   amdzone.it   ][   atizone.it   ][   forumzone.it   ][   hwsetup.it   ][   nvidiazone.it   ][   unixzone.it   ][   links   ][   feed rss   ][   chi siamo   ][   sitemap
NVIDIAZONE.IT è servito da una applicazione proprietaria di cui è vietata la replicazione parziale o totale (layout e/o logica). I marchi e le sigle in esso citate sono proprietà degli aventi diritto. Note Legali. Privacy.