VLC player fixes vulnerability that could allow remote code execution

VLC player fixes vulnerability that could allow remote code execution

VLC media player is a free and open source cross-platform multimedia player that plays most multimedia files as well as discs, devices, and network streaming.

It supports many new devices inputs, formats, metadata and improves most of the current ones, preparing for the next-gen codecs. For subtitles you can download VLSub.

Why is VLC so popular?

VLC Media Player has grown its user base over the years thanks to its simplicity, wide support for a variety of formats, and features which allow all sorts of video manipulation and enhancements.

Is VLC compatible with Windows 11?

VLC media player is compatible with all versions of Windows, including Windows 11. VLC player is a cross-platform media player, so it’s also available for macOS, Linux and Android.

What does VLC stand for?

VLC stands for VideoLAN Client. VLC media player, as it’s now called, began to exist around 1996 as a project from the École Centrale Paris consisting of a client and server designed to stream videos.

What video formats does VLC support?

VLC offers support for the following video formats: MPEG-1/2, DivX (1/2/3/4/5/6), MPEG-4 ASP, XviD, 3ivX D4, H.261, H.263 / H.263i, H.264 / MPEG-4 AVC, Cinepak, Theora, Dirac / VC-2, MJPEG (A/B), WMV 1/2, WMV 3 / WMV-9 / VC-1, Sorenson 1/3, DV, On2 VP3/VP5/VP6, Indeo Video v3 (IV32), Real Video (1/2/3/4).

What audio formats does VLC support?

VLC player offers support for the following audio formats: MPEG Layer 1/2, MP3 – MPEG Layer 3, AAC – MPEG-4 part3, Vorbis, AC3 – A/52, E-AC-3, MLP / TrueHD>3, DTS, WMA 1/2, WMA 3, FLAC, ALAC, Speex, Musepack / MPC, ATRAC 3, Wavpack, Mod, TrueAudio, APE, Real Audio, Alaw/µlaw, AMR (3GPP), MIDI, LPCM, ADPCM, QCELP, DV Audio, QDM2/QDMC, MACE.

Can VLC play DVDs?

VLC can play all kinds of DVDs, including discs with protection. However, the legality of using VLC to play protected DVDs depends on where you are located.

What’s New

Decoders:

Improve Opus ambisonic support
Fix some ASS subtitle rendering issues
Fix Opus in MP4 behaviour
Fix VAAPI hw decoding with some drivers

Input:

Add support for HTTP content range handling according to RFC 9110
Fix some HLS Adaptive Streaming not working in audio-only mode

Video Output:

Super Resolution scaling with AMD GPUs
The D3D11 HDR option can also turn on/off HDR for all sources regardless of the display
Improve subtitles rendering on Apple platforms of notably Asian languages by correcting font fallback lookups

Video Filter:

New AMD VQ Enhancer filter
Add D3D11 option to use NVIDIA TrueHDR to generate HDR from SDR sources

Audio Output:

Fix regression on macOS causing crashes when using audio devices with more than 9 channels

Services Discovery:

Fix exposed UPnP directory URL schemes to be compliant with RFC 3986

Contrib:

Update FFmpeg to 4.4.4
Update dav1d to 1.4.2
Update libvpx to 1.14.1

libVLC:

The HWND passed to libvlc_media_player_set_hwnd must have the WS_CLIPCHILDREN style set.
Fix crashes when using caopengllayer

Misc:

Fix various warnings, leaks and potential crashes
Fix security integer overflow in MMS module

Security:

A denial of service through a potential integer overflow could be triggered with a maliciously crafted mms stream (heap based overflow)

Impact

If successful, a malicious third party could trigger either a crash of VLC or an arbitratry code execution with the privileges of the target user.
While these issues in themselves are most likely to just crash the player, we can’t exclude that they could be combined to leak user informations or remotely execute code. ASLR and DEP help reduce the likelyness of code execution, but may be bypassed.
We have not seen exploits performing code execution through this vulnerability.

Threat mitigation

Exploitation of those issues requires the user to explicitly open a maliciously crafted mms stream.

Workarounds

The user should refrain from opening mms streams from untrusted third parties (or disable the VLC browser plugins), until the patch is applied.

Solution

VLC media player 3.0.21 addresses the issue.

Previous Release Notes:

Decoders:

NvidiaImprove Opus ambisonic support
NvidiaFix some ASS subtitle rendering issues
NvidiaFix Opus in MP4 behaviour
NvidiaFix VAAPI hw decoding with some drivers

Input:

NvidiaAdd support for HTTP content range handling according to RFC 9110
NvidiaFix some HLS Adaptive Streaming not working in audio-only mode

Video Output:

NvidiaSuper Resolution scaling with AMD GPUs
NvidiaThe D3D11 HDR option can also turn on/off HDR for all sources regardless of the display
NvidiaImprove subtitles rendering on Apple platforms of notably Asian languages by correcting font fallback lookups

Video Filter:

NvidiaNew AMD VQ Enhancer filter
NvidiaAdd D3D11 option to use NVIDIA TrueHDR to generate HDR from SDR sources

Audio Output:

NvidiaFix regression on macOS causing crashes when using audio devices with more than 9 channels

Services Discovery:

NvidiaFix exposed UPnP directory URL schemes to be compliant with RFC 3986

Contrib:

NvidiaUpdate FFmpeg to 4.4.4
NvidiaUpdate dav1d to 1.4.2
NvidiaUpdate libvpx to 1.14.1

libVLC:

Nvidiathe HWND passed to libvlc_media_player_set_hwnd must have the WS_CLIPCHILDREN
style set.
NvidiaFix crashes when using caopengllayer

Misc:

NvidiaFix various warnings, leaks and potential crashes
NvidiaFix security integer overflow in MMS module

Fast servers and clean downloads.

Serving tech enthusiasts for over 25 years.

Tested on TechSpot Labs.

Last updated:

June 13, 2024

OS:

Windows, macOS, Linux

User rating:

4.3 stars out of 5

279 votes

Recent VLC Media Player news

The “best” AV1 software decoder is being released via an over-the-air update

Arriving with the next Radeon driver update and a Q1 2024 VLC update

VLC Media Player is featured in…

Run From the Cloud or USB Drive — Favorite Portable Apps!

Desktop Software Essentials, So You’re Ready to Go

Software similar to VLC Media Player 29

4.5 stars out of 5

166 votes

Multimedia player that supports a variety of different video codecs and formats.

Freeware

Windows

4.5 stars out of 5

778 votes

Versatile media player which can cover various types of container format such as VCD, DVD, AVI, WMV among others. Windows 64-bit version also available here.

Freeware

Windows, Android

4.4 stars out of 5

13875 votes

Play all your music, video and sync content to your iPhone, iPad, and Apple TV. iTunes 2024 is a free application for Windows and macOS.

Freeware

Windows

More similar downloads

>>> Read full article>>>
Copyright for syndicated content belongs to the linked Source : TechSpot – https://www.techspot.com/downloads/3562-vlc-media-player.html

Exit mobile version