An unscheduled patch release of VLC media player 3.0.20 is available, which fixes a potential vulnerability (CVE not assigned) that could lead to the writing of data outside the buffer when parsing malformed network packets in the MMSH (Microsoft Media Server over HTTP) streaming handler. This vulnerability could theoretically be exploited when attempting to load content from malicious servers using the URL 'mms://'.
In addition to security issues, the new release also addresses the following problems:
- Crash on systems with certain versions of AMD GPU drivers;
- Crash during unsuccessful attempts to use the AV1 hardware decoder;
- Appearance of a green line during fullscreen playback via D3D11 on Windows;
- Crashes when double-clicking the mouse wheel;
- Disappearance of the toolbar in fullscreen mode on Windows.
Source: opennet.ru
