From gitlab at videolan.org Mon May 10 07:33:27 2021
From: gitlab at videolan.org (Jean-Baptiste Kempf)
Date: Mon, 10 May 2021 09:33:27 +0200
Subject: [www-doc] [Git][VideoLAN.org/websites][master] 6 commits: security:
Add a SB for 3.0.13
Message-ID: <6098e1c7b3dda_93738fcfcd040037f0@gitlab.mail>
Jean-Baptiste Kempf pushed to branch master at VideoLAN organization / websites
Commits:
027fedde by Hugo Beauzée-Luyssen at 2021-04-27T16:23:54+02:00
security: Add a SB for 3.0.13
- - - - -
883d694f by Hugo Beauzée-Luyssen at 2021-04-27T16:23:54+02:00
vlc: Add a 3.0.13 release page
- - - - -
7e74744a by Hugo Beauzée-Luyssen at 2021-04-27T16:23:54+02:00
vlc: Add 3.0.13 download counters
- - - - -
2930829e by Hugo Beauzée-Luyssen at 2021-04-27T16:23:54+02:00
vlc: Add 3.0.13 to the releases list
- - - - -
2e55f18d by Hugo Beauzée-Luyssen at 2021-05-03T12:05:23+02:00
news: Add 3.0.13 release
- - - - -
900f6383 by Hugo Beauzée-Luyssen at 2021-05-03T12:16:10+02:00
Release 3.0.13
- - - - -
7 changed files:
- www.videolan.org/include/os-specific.php
- www.videolan.org/news.msg
- www.videolan.org/security/index.php
- + www.videolan.org/security/sb-vlc3013.php
- + www.videolan.org/vlc/releases/3.0.13.php
- www.videolan.org/vlc/releases/index.php
- www.videolan.org/vlc/stats/downloads.php
Changes:
=====================================
www.videolan.org/include/os-specific.php
=====================================
@@ -1,10 +1,10 @@
the release page.
+
|05 April 2021|libbluray 1.3.0|A new release of libbluray was pushed today, adding new APIs, to improve the control of the library, improve platforms support, and fix some bugs. See our libbluray page.
|1st February 2021|VideoLAN is 20 years old today!|20 years ago today, VideoLAN moved from a closed-source student project to the GNU GPL, thanks to the authorization of the École Centrale Paris director at that time.
VLC has grown a lot since, thanks to 1000 volunteers!
Read our press release!.
=====================================
www.videolan.org/security/index.php
=====================================
@@ -21,6 +21,10 @@
Those bulletins are related to each VLC release and can be made of multiple security issues, internal and external.
+Summary : Multiple vulnerabilities fixed in VLC media player +Date : April 2021 +Affected versions : VLC media player 3.0.12 and earlier +ID : VideoLAN-SB-VLC-3013 ++ +
A remote user could create a specifically crafted file that could trigger some various issues.
+It is possible to trigger a remote code execution through a specifically crafted playlist, and tricking the user into interracting with that playlist elements.
+This is explained in more details on the reporter's article
+It is also possible to trigger read or write buffer overflows with some crafted files or by a MITM attack on the automatic updater
+ +If successful, a malicious third party could trigger either a crash of VLC or an arbitratry code execution with the privileges of the target user.
+While these issues in themselves are most likely to just crash the player, we can't exclude that they could be combined to leak user informations or +remotely execute code. ASLR and DEP help reduce the likelyness of code execution, but may be bypassed.
+We have not seen exploits performing code execution through these vulnerability
+Exploitation of those issues requires the user to explicitly open a specially crafted file or stream.
+ +The user should refrain from opening files from untrusted third parties +or accessing untrusted remote sites (or disable the VLC browser plugins), +until the patch is applied. +
+ +VLC media player 3.0.13 addresses the issue. +
+ +The playlist based RCE was reported by Fabian Bräunlein and Lukas Euler from positive.security
+The AV1 in MP4 buffer overflow was reported by Zhen Zhou, NSFOCUS Security Team
+The invalid free() in the kate decoder was reported by Jordan Milne
+The updater system buffer overflow was reported by Fabian Yamaguchi
+ +VLC 3.0 playing 8K 48fps 360 video on Android Galaxy S8 from VideoLAN on Vimeo.
+VLC 3.0 playing 8k60 on Windows 10 using i7 GPU from VideoLAN on Vimeo.
+Ask your favorite packager for VLC 3.0!
+For any questions related to this release, please contact us.
+This notice applies to VLC 3.0.13 and VLC 3.0.12 users.
+Due to an incorrect change in the automatic updater code, updates will be downloaded, verified for integrity, but will not be installed. This is bad and we're sorry.
Ask your favorite packager for VLC 3.0!
+For any questions related to this release, please contact us.
+This notice applies to VLC 3.0.13 and VLC 3.0.12 users.
@@ -70,10 +71,11 @@ Due to an incorrect change in the automatic updater code, updates will be downlo
This notice applies to VLC 3.0.13 and VLC 3.0.12 users.
-Due to an incorrect change in the automatic updater code, updates will be downloaded, verified for integrity, but will not be installed. This is bad and we're sorry.
Ask your favorite packager for VLC 3.0!
+For any questions related to this release, please contact us.
+Ask your favorite packager for VLC 3.0!
+For any questions related to this release, please contact us.
+Ask your favorite packager for VLC 3.0!
+For any questions related to this release, please contact us.
+Esse aviso é relevante para utilizadores do VLC 3.0.13 e VLC 2.0.12. Devido a um defeito introduzido no códico do atualizador automático, a atualização é baixada, verificada mas não é installada. Isto é mau e nós pedirmos desculpas por isso.
+Em 10 de maio de 2021 a organização VideoLAN publicou a versão 3.0.13 do VLC e ativou a atualização automatica. Isso normalmente é simples, uma janela iria aparecer com a informação sobre a nóva versão, você clique baixar e instalar e é isso. Contudo e infelizmente, para essa atualização particular, alguns passos addiçionais serão necessários. O problema é introduzido na versão 3.0.12, mas não se tornou óbvio até publicar a versão 3.0.13. Enquanto o problema é resolvido na versão 3.0.14, não é possivel fiar-se nisso para usários que já instalaram a versão 3.0.12.
+Ask your favorite packager for VLC 3.0!
+For any questions related to this release, please contact us.
+Esse aviso é relevante para utilizadores do VLC 3.0.13 e VLC 2.0.12. Devido a um defeito introduzido no códico do atualizador automático, a atualização é baixada, verificada mas não é installada. Isto é mau e nós pedirmos desculpas por isso.
+Esse aviso é relevante para utilizadores do VLC 3.0.13 e VLC 2.0.12. Devido a um defeito introduzido no códico do atualizador automático, a atualização é baixada, verificada mas não é installada. Isto é mau e nós pedirmos desculpas por isso.Em 10 de maio de 2021 a organização VideoLAN publicou a versão 3.0.13 do VLC e ativou a atualização automatica. Isso normalmente é simples, uma janela iria aparecer com a informação sobre a nóva versão, você clique baixar e instalar e é isso. Contudo e infelizmente, para essa atualização particular, alguns passos addiçionais serão necessários. O problema é introduzido na versão 3.0.12, mas não se tornou óbvio até publicar a versão 3.0.13. Enquanto o problema é resolvido na versão 3.0.14, não é possivel fiar-se nisso para usários que já instalaram a versão 3.0.12.
+Em 10 de maio de 2021 a organização VideoLAN publicou a versão 3.0.13 do VLC e ativou a atualização automatica.VLC media player requires Mac OS X 10.7.5 or later. It runs on any Mac with a 64-bit Intel processor or an Apple Silicon chip. Previous devices are supported by older releases.
Note that the first generation of Intel-based Macs equipped with Core Solo or Core Duo processors is no longer supported. Please use version 2.0.10 linked below.
If you need help in finding the correct package matching your Mac's processor architecture, please see this official support document by Apple.
+If you need help in finding the correct package matching your Mac's processor architecture, please see this official support document by Apple. You can also choose to install a Universal Binary.
Support for NPAPI plugins was removed from all modern web browsers, so VLC's plugin is no longer maintained. The last version is 3.0.4 and can be found here. It will not receive any further updates.
===================================== www.videolan.org/vlc/releases/3.0.12-update.de.php ===================================== @@ -9,7 +9,7 @@ require($_SERVER["DOCUMENT_ROOT"]."/include/header.php"); require($_SERVER["DOCUMENT_ROOT"]."/include/package.php"); - $macosxversion = "3.0.13"; + $macosxversion = "3.0.14"; $win32version = "3.0.14"; ?>Ask your favorite packager for VLC 3.0!
+For any questions related to this release, please contact us.
+Ask your favorite packager for VLC 3.0!
+For any questions related to this release, please contact us.
+'; - echo preg_replace(array('^(http://\S+)^is', '^(https://\S+)^is'), '$1', str_replace("videolan:", "" . date("Y-m-d h:i", strtotime($item['pubdate'])) . "", $item['title'])); - echo "
"; - $i++; - if ($i >= $columns * $entries_per_column) break; - if ($i % $entries_per_column == 0) echo "'; + echo preg_replace(array('^(http://\S+)^is', '^(https://\S+)^is'), '$1', str_replace("videolan:", "" . date("Y-m-d h:i", strtotime($item['pubdate'])) . "", $item['title'])); + echo "
"; + $i++; + if ($i >= $columns * $entries_per_column) break; + if ($i % $entries_per_column == 0) echo "Could not load RSS feed
"; ?> ===================================== www.videolan.org/vlc/skins.php ===================================== @@ -1,9 +1,15 @@ \n"; } -$query = 'SELECT downloads, size FROM skins_pack WHERE id=0'; -$q = pg_query( $connect, $query ); -$r = pg_fetch_array( $q ); -$sp_dl = $r['downloads']; -$sp_size = FormatSize( $r['size'] ); +if ( $connect != false ) +{ + $query = 'SELECT downloads, size FROM skins_pack WHERE id=0'; + $q = pg_query( $connect, $query ); + $r = pg_fetch_array( $q ); + $sp_dl = $r['downloads']; + $sp_size = FormatSize( $r['size'] ); +} +else +{ + $sp_dl = 0; + $sp_size = 0; +} ?> - - -- Get the source! -
-- Ask your favorite packager for VLC 3.0! -
-irc.freenode.org
+ Our live-chat IRC channel on the Libera.chat Network:irc.libera.chat
Channel: #videolan
- Use the Freenode Web interface, if you don't have an IRC client at hand.
+ Use the KiwiIRC Web interface, if you don't have an IRC client at hand.
+ Just pick a pseudo and connect without password. +
+ Connect using WebIRC +
+ Our channel is on Libera.chat Network
+ Server: irc.libera.chat
+ Channel: #videolan
+ URI: ircs://irc.libera.chat:6697
+
+ Just pick a pseudo and connect without password. +
+ Connect using WebIRC +
+ Our channel is on Libera.chat Network
+ Server: irc.libera.chat
+ Channel: #videolan
+ URI: ircs://irc.libera.chat:6697
+
MobileVLCKit iOS nightly builds for ARMv7, ARMv7s, AArch64, x86_64 and i686
Remember to test the latest nightly build before reporting a bug (in one of the older nightly builds). Have fun!
-Please report nightly builds breakage (meaning that there is no new build) on #videolan
on irc.freenode.net.
Please report nightly builds breakage (meaning that there is no new build) on #videolan
on irc.libera.chat.
Note: MobileVLCKit's nightly builds for iOS require iOS 7 or later as well as Xcode 7.3 or later
The static framework will not work on earlier releases of iOS. Linking with libc++ instead of libstdc++ is required.
===================================== nightlies.videolan.org/build/macosx-intel/HEADER.html ===================================== @@ -6,7 +6,7 @@VLC media player nightly builds for macOS
Remember to test the latest nightly build before reporting a bug (in one of the older nightly builds). Have fun!
-Please report nightly builds breakage (meaning that there is no new build) on #videolan
on irc.freenode.net
.
Please report nightly builds breakage (meaning that there is no new build) on #videolan
on irc.libera.chat
.
Note: VLC's nightly builds require at least macOS 10.7 for VLC 3.0.x (stable version) or macOS 10.11 for VLC 4.0.0 (development version)
It will not launch on older releases. We recommend you to keep your Mac OS X installation up-to-date and to install Apple's updates. This will also improve your VLC usage experience.
===================================== nightlies.videolan.org/build/tvOS/HEADER.html ===================================== @@ -6,7 +6,7 @@TVVLCKit tvOS nightly builds for AArch64 and x86_64
Remember to test the latest nightly build before reporting a bug (in one of the older nightly builds). Have fun!
-Please report nightly builds breakage (meaning that there is no new build) on #videolan
on irc.freenode.net.
Please report nightly builds breakage (meaning that there is no new build) on #videolan
on irc.libera.chat.
Note: TVVLCKit's nightly builds require tvOS 9 or later as well as Xcode 7.3 or later
Linking with libc++ instead of libstdc++ is required.
Looking for nightly builds for other OSes or official releases?
===================================== nightlies.videolan.org/build/win32/HEADER.html ===================================== @@ -7,7 +7,7 @@VLC media player Win32 nightly builds
Remember to test the latest nightly build before reporting a bug (in one of the older nightly builds). Have fun!
-Please report nightly builds breakage (meaning that there is no new build) on #videolan
on irc.freenode.net
.
Please report nightly builds breakage (meaning that there is no new build) on #videolan
on irc.libera.chat
.
What's the stable branch?
VLC media player Win64 nightly builds
Remember to test the latest nightly build before reporting a bug (in one of the older nightly builds). Have fun!
-Please report nightly builds breakage (meaning that there is no new build) on #videolan
on irc.freenode.net
.
Please report nightly builds breakage (meaning that there is no new build) on #videolan
on irc.libera.chat
.
What's the stable branch?
Remember to test the latest nightly build before reporting a bug (in one of the older nightly builds). Have fun!
-Please report nightly builds breakage (meaning that there is no new build) on #videolan
on irc.freenode.net.
Please report nightly builds breakage (meaning that there is no new build) on #videolan
on irc.libera.chat.
Looking for nightly builds for other OSes or official releases?
===================================== www.videolan.org/developers/index.php ===================================== @@ -49,7 +49,7 @@ or on the Mailing-lists. - +vlc-devel at videolan.org
, or try to meet the developers
on IRC (#videolan
, irc.videolan.org
or
-any Freenode server) if you want to help us but don't know where to
+any Libera Chat server) if you want to help us but don't know where to
start.
You can also ask questions in the development mailing-list
vls-devel at videolan.org
, or try to meet the developers
on IRC (#videolan
, irc.videolan.org
or
-any Freenode server) if you want to help us but don't know where to
+any Libera Chat server) if you want to help us but don't know where to
start.
We'd like to thank all our contributors, testers and users around the world for their support and help making this release possible. @@ -496,7 +496,7 @@ Help is available, as usual, in many places:
Binary packages for Mac OS X and Windows, as well as source code tarballs are available for download.
Help is available, as usual, in many places:
We'd like to thank all our contributors, testers and users around the world for their support and help making this release possible.
We are putting out a call for NEW Windows developers. At the moment, our Windows-port is sorely missing some much needed love from a true Windows developer. Our team has been without a Windows developer for several months now, which is blocking us from supporting our largest usergroup in the manner we want to. We are therefore looking for developers to help our team in the areas of debugging crashes, Direct X, A/V capturing, ActiveX and Windows integration, so we can hopefully resume supporting our largest group of users in the best possible way. If we are unable to find new developers, new versions of VLC media player for Windows might become less frequent and severely out of sync with the Linux and Mac OS X versions.
So, no donations for work on the Windows-port and no "opportunities"-emails, for Windows we only require: Developers, Developers, Developers !!!!!
@@ -520,7 +520,7 @@ Binary packages for Mac OS X and source c
We'd like to thank all our contributors, testers and users around the world for their support and help making this release possible.
We are putting out a call for NEW Windows developers. At the moment, our Windows-port is sorely missing some much needed love from a true Windows developer. Our team has been without a Windows developer for several months now, which is blocking us from supporting our largest usergroup in the manner we want to. We are therefore looking for developers to help our team in the areas of debugging crashes, Direct X, A/V capturing, ActiveX and Windows integration, so we can hopefully resume supporting our largest group of users in the best possible way. If we are unable to find new developers, new versions of VLC media player for Windows might become less frequent and severely out of sync with the Linux and Mac OS X versions.
@@ -544,7 +544,7 @@ A comprehensive list of
Binary packages for Windows and Mac OS X, as well as source code tarballs are available for download.
Help is available, as usual, in many places:
We'd like to thank all our contributors, testers and users around the world for their support and help making this release possible.
|30 August 2008| VideoLAN Security Advisory 0807 | VLC media player versions 0.8.6i and older suffer from multiple buffer overflow vulnerabilities. Refer to our advisory for technical details. Fixes for these issues are available in VLC 0.9. We strongly recommend all users to update to this new version.
Note: a binary VLC 0.9 release should be available for Windows and Mac OS X users in a few days.
@@ -596,7 +596,7 @@ Have a look here for the f
Binary packages and the source code are available on the
VLC download page.
You can get help concerning this new release on the Documentation Page, Forum, Wiki, Mailing Lists or in #videolan on Freenode.
+href="/support/lists.html" >Mailing Lists
To contribute, check out the contribution document.
Most of the development discussion happens on IRC, in the #dav1d
- channel on Freenode.
The code can be found on the VideoLAN Gitlab:
git clone https://code.videolan.org/videolan/dav1d.git
View it on GitLab: https://code.videolan.org/VideoLAN.org/websites/-/commit/638d7206c9ebe449401c556c1a809518e5622ca8
--
View it on GitLab: https://code.videolan.org/VideoLAN.org/websites/-/commit/638d7206c9ebe449401c556c1a809518e5622ca8
You're receiving this email because of your account on code.videolan.org.