Alleged VLC security flaw denied by developers

SHARE:

News broke out today that the VLC Media Player has a potentially serious security flaw. Various media outlets have even asked their readers ...

News broke out today that the VLC Media Player has a potentially serious security flaw. Various media outlets have even asked their readers to stay away from the media player and outright adviced readers to uninstall it as the flaw can reportedly be used to launch remote code executions, corrupt files, steal data, and do a lot more damage. However, there is another side of the story being told by VLC developers, which hasn’t been reported as widely yet. 

The security flaw, CVE-2019-13615, was apparently discovered in version 3.0.7.1 of VLC by CVE and reported by CERT-Bund. The vulnerability currently has a NIST threat score of 9.8 out of 10, which classifies it as a critical threat. As explained by CVE, the flaw requires you to play a malformed MKV file and in theory, if one downloads a malicious MKV file, the VLC bug could be used to execute code remotely and cause damage ranging from data theft to service disruption. The macOS version of the software doesn’t seem to be affected and there have been no reports of the flaw being misused yet. 

However, there's more to the story. VLC developers claim that the original exploit report is incorrect since they already fixed the flaw with version 3.0.3 of the app.

Lead VLC developer, Jean-Baptiste Kempf commented that the alleged bug isn’t as big of a deal as everyone is making it out to be. In a comment, he also wrote - “This does not crash a normal release of VLC 3.0.7.1.” Another VLC developer, Francois Cartegnie, wrote, “If you land on this ticket through a news article claiming a critical flaw in VLC, I suggest you to read the above comment first and reconsider your (fake) news sources.”

VideoLAN also took to Twitter to talk about the matter, and wrote "a reporter, opened a bug on our bugtracker, which is outside of the reporting policy, aka, mail us in private on the security alias." They further added, "the reporter is using Ubuntu 18.04, which is an old version of Ubuntu, and clearly has not all the updated libraries." You can check their official statements in the thread mentioned below.

About the "security issue" on #VLC : VLC is not vulnerable. tl;dr: the issue is in a 3rd party library, called libebml, which was fixed more than 16 months ago. VLC since version 3.0.3 has the correct version shipped, and @MITREcorp did not even check their claim. Thread:

— VideoLAN (@videolan) 24 July 2019 

from Latest Technology News https://ift.tt/2SD8PR7

COMMENTS

Name

7,1,Airtel,1,Andriod,1,Android,4,Android Q,1,apex,1,Apple,7,Apps,1,Asus Rog,1,Black Shark 2,2,Boeing 737 MAX,1,Bsnl,2,camera,2,CPU,3,Donald Trump,1,Earphone,1,Facebook,5,Fan,1,Fitbit,1,foldable Phone,2,Fortnite,1,Galaxy A40,1,Galaxy s10,1,Galaxy s10e,1,Games,10,gaming,1,Google,6,Google Pixel 2,1,Honor 10i,1,Huawe,1,Huawei,6,Huawei GT,1,IBM,1,Instagram,2,Internet,2,ios,2,iPad,2,iphone,2,Israel,1,jiomart,1,Laptop,1,Leica Q2,1,M20,1,mac,1,MacOS,1,Mi 9,1,Mi A2,1,Mi LED TV,1,MicroSoft,3,mobile,1,Moon,2,Mozilla,1,Nasa,2,News,1,Nokia,4,Nokia 62,1,Nvidias,1,OnePlus,4,Oppo,5,P30,3,Pixel,1,Poco F1,1,Pubg,12,Qualcomm,2,Redmi 3,1,Redmi 6 Pro,1,Redmi 7,1,Redmi Note 7,1,reliance,1,Reno,1,samsung,11,Skype,1,SmartPhone,56,Social,5,Spotify,1,Tech,35,Telecom,3,Touchpad,1,Tournament,1,TV,1,Twitter,1,Vivo,2,Watch,2,WhatsApp,1,Xbox,1,Xiaomi,16,y9li,1,
ltr
item
Genius Baba: Alleged VLC security flaw denied by developers
Alleged VLC security flaw denied by developers
http://feeds.feedburner.com/~r/digit/latest-news/~4/dsCyz7ywWPk
Genius Baba
https://geniusbabaa.blogspot.com/2019/07/alleged-vlc-security-flaw-denied-by.html
https://geniusbabaa.blogspot.com/
https://geniusbabaa.blogspot.com/
https://geniusbabaa.blogspot.com/2019/07/alleged-vlc-security-flaw-denied-by.html
true
7104319406113350277
UTF-8
Loaded All Posts Not found any posts VIEW ALL Readmore Reply Cancel reply Delete By Home PAGES POSTS View All RECOMMENDED FOR YOU LABEL ARCHIVE SEARCH ALL POSTS Not found any post match with your request Back Home Sunday Monday Tuesday Wednesday Thursday Friday Saturday Sun Mon Tue Wed Thu Fri Sat January February March April May June July August September October November December Jan Feb Mar Apr May Jun Jul Aug Sep Oct Nov Dec just now 1 minute ago $$1$$ minutes ago 1 hour ago $$1$$ hours ago Yesterday $$1$$ days ago $$1$$ weeks ago more than 5 weeks ago Followers Follow THIS PREMIUM CONTENT IS LOCKED STEP 1: Share. STEP 2: Click the link you shared to unlock Copy All Code Select All Code All codes were copied to your clipboard Can not copy the codes / texts, please press [CTRL]+[C] (or CMD+C with Mac) to copy