The release of VLC Media Player 3.0.18 has been announced, which addresses four vulnerabilities that could potentially allow an attacker to execute code when handling specially crafted files or streams. The most dangerous vulnerability (CVE-2022-41325) could lead to a buffer overflow when loading via the vnc URL. The other vulnerabilities, which manifest while processing files in mp4 and ogg formats, are likely to be only exploitable for denial of service.
Among other non-security related changes:
- Significantly improved support for adaptive streaming.
- Added support for RISC-V architecture.
- Enhanced functionality with SMBv1, SMBv2, and FTP protocols.
- Fixed issues when seeking in OGG and MP4 formats. Established compatibility with Windows Media Player for the AVI format. Resolved an issue that hindered playback of certain Flac files.
- Added support for DVBSub subtitles in MKV.
- Added support for Y16 color space.
- Updated codecs and libraries: FFmpeg, bluray, upnp, pthread, x265, freetype, libsmb2, aom, dav1d, libass, libxml2, dvdread, harfbuzz, zlib, gme, nettle, GnuTLS, mpg123, speex, bluray, libvpx.
- Fixed issues with window resizing and color accuracy when outputting using OpenGL.
- Resolved compatibility issues with some older GPUs.
Source: opennet.ru
