venerdì 04 aprile 2025 02:38 mobile  |  3dfxzone.it  |  amdzone.it  |  atizone.it  |  forumzone.it  |  hwsetup.it  |  nvidiazone.it  |  unixzone.it  
UNIXZONE.IT
            proudly powered by 3dfxzone.it
Home    |    News    |    Headlines    |    Articoli    |    Download    |    Community    |    Redazione    |    Condividi    |    Tag    |    Ricerca    |    Sitemap

Pubblicità Informazioni e Release Notes del file: VLC Media Player 3.0.7 Ultime News
Condividi su Facebook Condividi su Twitter Condividi su WhatsApp Condividi su reddit

We just released VLC 3.0.7, a minor update of VLC branch 3.0.x. This release is a bit special, because it has more security issues fixed than any other version of VLC.

This high number of security issues is due to the sponsoring of a bug bounty program funded by the European Commission, during the FOSSA program.

Severity

According to our scale, we have had 33 valid security issues fixed thanks to this program:

  • 2 high security issues, (only one was present in 3.0.x),
  • 21 medium security issues,
  • 20 low security issues.

The 2 more important issues are an Out-of-Bound Write and a Stack Buffer Overflow.

the Out-of-Bound Write is not in the VLC codebase, but in a dependency of VLC, the faad2 library, unmaintained, unfortunately.

the Stack Buffer Overflow is a VLC 4.0-only issue in the new RIST module, and is therefore not impacting actual release of VLC.

The medium security issues are mostly out-of-band reads, heap overflows, NULL-dereference and use-after-free security issues. Those issues should not be exploitable with ASLR, but are important anyway, because they can crash VLC.

The low security issues are mostly integer overflow, division by zero, and other out-of-band reads with no actual impact. Those issues are not exploitable.

30.03.2025  
Con l'app free FileZilla Server 1.10.1 puoi creare un server FTP a costo zero
27.03.2025  
Con l'app free FileZilla Server 1.10 puoi creare il tuo server FTP a costo zero
25.03.2025  
The Linux Kernel Organization rilascia il Linux Kernel 6.14: info e download
22.03.2025  
Wine 10.4 esegue il software nativo per Windows su Linux, Unix e MacOS
20.03.2025  
Free & Open Source Image Editing: GIMP 3.0.0 - Windows & Linux & macOS
19.03.2025  
NVIDIA rilascia il package Linux X64 (AMD64/EM64T) Display Driver 570.133.07
18.03.2025  
NVIDIA lancia le card RTX PRO 6000 Blackwell e RTX PRO 6000 Blackwell Max-Q
16.03.2025  
SystemRescueCd 12.00 consente di ripristinare e configurare Linux e Windows
10.03.2025  
Free VoIP & Messaging Tools: Skype 8.138.0.203 - Windows, macOS, Linux, Android
09.03.2025  
NVIDIA, in arrivo la RTX PRO 6000, una card che batte anche la GeForce RTX 5090
The Linux Kernel Organization rilascia il Linux Kernel 6.13.6: info e download
08.03.2025  
Wine 10.3 esegue il software nativo per Windows su Linux, Unix e MacOS
05.03.2025  
Apple lancia la nuova linea di iPad Air da 11-inch e 13-inch con SoC M3
02.03.2025  
The Document Foundation rilascia la suite gratuita LibreOffice 25.2.1
28.02.2025  
NVIDIA rilascia il package Linux x64 (AMD64/EM64T) Display Driver 570.124.04
24.02.2025  
Apple annuncia iPhone 16e: foto, specifiche, prezzi e disponibilità sul mercato
The Linux Kernel Organization rilascia il Linux Kernel 6.14-rc4: info e download
Ventoy 1.1.05 consente di creare drive USB per avviare più Sistemi Operativi
22.02.2025  
GPU Shark 2.6.0 supporta GeForce RTX 5090, RTX 5080, RTX 5070 Ti e Arc B570
Wine 10.2 esegue il software nativo per Windows su Linux, Unix e MacOS
Indice delle news 
Ultimi File
Linux Kernel 6.14
AMD Radeon Software for Linux 24.20.3
Wine 10.4 [Development Release]
GIMP 3.0.0
GIMP 3.0.0
NVIDIA Linux X64 (AMD64/EM64T) Display Driver 570.133.07
Linux Kernel 6.13.6
Wine 10.3 [Development Release]
LibreOffice 25.2.1
NVIDIA Linux X64 (AMD64/EM64T) Display Driver 570.124.04
Indice dei file 
U N I X Z O N E . I T
3dfxzone.it         |       amdzone.it         |       atizone.it         |       forumzone.it         |       hwsetup.it         |       nvidiazone.it         |       unixzone.it         |       feed rss         |       links
unixzone.it è servito da una applicazione proprietaria di cui è vietata la riproduzione parziale o totale (layout e/o logica). I marchi e le sigle in esso citate sono proprietà degli aventi diritto. Note legali. Privacy.