venerdì 22 novembre 2024 14:34 mobile  |  3dfxzone.it  |  amdzone.it  |  atizone.it  |  forumzone.it  |  hwsetup.it  |  nvidiazone.it  |  unixzone.it  
AMDZONE.IT
 proudly powered by 3dfxzone.it
Home    |    News    |    Headlines    |    Articoli    |    Download    |    Community    |    Redazione    |    Condividi    |    Tag    |    Ricerca    |    Sitemap
ADV Informazioni e Release Notes del file: VLC Media Player 3.0.7 Ultime News
Condividi su Facebook Condividi su Twitter Condividi su WhatsApp Condividi su reddit

We just released VLC 3.0.7, a minor update of VLC branch 3.0.x. This release is a bit special, because it has more security issues fixed than any other version of VLC.

This high number of security issues is due to the sponsoring of a bug bounty program funded by the European Commission, during the FOSSA program.

Severity

According to our scale, we have had 33 valid security issues fixed thanks to this program:

  • 2 high security issues, (only one was present in 3.0.x),
  • 21 medium security issues,
  • 20 low security issues.

The 2 more important issues are an Out-of-Bound Write and a Stack Buffer Overflow.

the Out-of-Bound Write is not in the VLC codebase, but in a dependency of VLC, the faad2 library, unmaintained, unfortunately.

the Stack Buffer Overflow is a VLC 4.0-only issue in the new RIST module, and is therefore not impacting actual release of VLC.

The medium security issues are mostly out-of-band reads, heap overflows, NULL-dereference and use-after-free security issues. Those issues should not be exploitable with ASLR, but are important anyway, because they can crash VLC.

The low security issues are mostly integer overflow, division by zero, and other out-of-band reads with no actual impact. Those issues are not exploitable.

21.11.2024  
PDF24 Creator 11.21.0 converte doc e immagini in PDF, e rimuove pagine dai PDF
18.11.2024  
HDCleaner 2.083 è free e ripulisce drive di storage e registro di configurazione
16.11.2024  
GIGABYTE lancia la video card AMD Radeon PRO W7800 AI TOP 48G
14.11.2024  
System Information Utilities: SIV (System Information Viewer) 5.7
Hardware Monitoring & Benchmark: AIDA64 Extreme Edition 7.40.7108 beta
13.11.2024  
Free USB Utilities: USB Drive Letter Manager (USBDLM) 5.6.3 - x86/x64 Ready
11.11.2024  
Free VoIP & Messaging Tools: Skype 8.132.0.201 - Windows, macOS, Linux, Android
Benchmark & Testing Utilities: Passmark PerformanceTest 11.0 build 1024
08.11.2024  
OpenGL & Vulkan Information Tools: GLview (ex OpenGL Extensions Viewer) 7.2.8
07.11.2024  
OpenGL Testing & Benchmark GPU Tools: FurMark OpenGL Benchmark 2.4.3.0
06.11.2024  
Free PDF Viewing & Printing Tools: Adobe Acrobat Reader DC 2024.004.20243
OpenGL Testing & Benchmark GPU Tools: FurMark OpenGL Benchmark 2.4.2.0
CPU & Memory & Motherboard Information Tools: CPU-Z 2.12 - AMD & Intel Ready
05.11.2024  
Hardware Testing & Benchmark Tools: Passmark BurnInTest 11 build 1003
04.11.2024  
RegCool 2.015 esegue ricerche, crea backup e modifica il registro di Windows
03.11.2024  
Autorun Organizer 5.46 può aiutare a ridurre il tempo di caricamento di Windows
02.11.2024  
OpenGL & Vulkan Information Tools: GLview (ex OpenGL Extensions Viewer) 7.2.7
01.11.2024  
AMD rilascia il driver grafico Radeon Software Adrenalin Edition 24.20.19.05
30.10.2024  
Free PDF Viewing & Printing Tools: Adobe Acrobat Reader DC 2024.004.20220
29.10.2024  
ASUS introduce la video card non reference Radeon RX 7600 DUAL EVO OC
Indice delle news 
Ultimi File
PDF24 Creator 11.21.0
HDCleaner 2.083
Adobe Acrobat Reader DC 2024.004.20272
Intel Arc & Iris Xe Graphics Driver 32.0.101.6297
SIV (System Information Viewer) 5.78
AIDA64 Extreme Edition 7.40.7108 beta
Passmark PerformanceTest 11.0 build 1024
GLview (ex OpenGL Extensions Viewer) 7.2.8
FurMark 2 2.4.3.0
CPU-Z 2.12
Passmark BurnInTest 11 build 1003
RegCool 2.015
Indice dei file 
A M D Z O N E . I T
3dfxzone.it         |       amdzone.it         |       atizone.it         |       forumzone.it         |       hwsetup.it         |       nvidiazone.it         |       unixzone.it         |       feed rss         |       links
AMDZone.it è servito da una applicazione proprietaria di cui è vietata la riproduzione parziale o totale (layout e/o logica). I marchi e le sigle in esso citate sono proprietà degli aventi diritto. Note legali. Privacy.