ALT-BU-2018-3671-1
Branch sisyphus update bulletin.
Closed vulnerabilities
BDU:2019-01262
Уязвимость демультиплексера CAF медиа плеера VideoLAN VLC, связанная с доступом к неинициализированному указателю, позволяющая нарушителю вызвать отказ в обслуживании и/или получить доступ к конфиденциальным данным
Modified: 2024-11-21
CVE-2018-19857
The CAF demuxer in modules/demux/caf.c in VideoLAN VLC media player 3.0.4 may read memory from an uninitialized pointer when processing magic cookies in CAF files, because a ReadKukiChunk() cast converts a return value to an unsigned int even if that value is negative. This could result in a denial of service and/or a potential infoleak.
- openSUSE-SU-2019:1840
- openSUSE-SU-2019:1840
- openSUSE-SU-2019:1897
- openSUSE-SU-2019:1897
- openSUSE-SU-2019:1909
- openSUSE-SU-2019:1909
- openSUSE-SU-2019:2015
- openSUSE-SU-2019:2015
- 106130
- 106130
- https://dyntopia.com/advisories/013-vlc
- https://dyntopia.com/advisories/013-vlc
- https://git.videolan.org/?p=vlc.git%3Ba=commit%3Bh=0cc5ea748ee5ff7705dde61ab15dff8f58be39d0
- https://git.videolan.org/?p=vlc.git%3Ba=commit%3Bh=0cc5ea748ee5ff7705dde61ab15dff8f58be39d0
- USN-4074-1
- USN-4074-1
- DSA-4366
- DSA-4366
Closed vulnerabilities
BDU:2019-03229
Уязвимость функции сжатия библиотеки для сжатия данных Zstandard, позволяющая нарушителю выполнить произвольный код
Modified: 2024-11-21
CVE-2019-11922
A race condition in the one-pass compression functions of Zstandard prior to version 1.3.8 could allow an attacker to write bytes out of bounds if an output buffer smaller than the recommended size was used.
- openSUSE-SU-2019:1845
- openSUSE-SU-2019:1845
- openSUSE-SU-2019:1952
- openSUSE-SU-2019:1952
- openSUSE-SU-2019:2008
- openSUSE-SU-2019:2008
- https://github.com/facebook/zstd/pull/1404/commits/3e5cdf1b6a85843e991d7d10f6a2567c15580da0
- https://github.com/facebook/zstd/pull/1404/commits/3e5cdf1b6a85843e991d7d10f6a2567c15580da0
- USN-4108-1
- USN-4108-1
- https://www.facebook.com/security/advisories/cve-2019-11922
- https://www.facebook.com/security/advisories/cve-2019-11922
- https://www.oracle.com/security-alerts/cpuoct2020.html
- https://www.oracle.com/security-alerts/cpuoct2020.html