Release of media player VLC 3.0.24 with 130 vulnerabilities fixed

The release of the multimedia player VLC 3.0.24 has been announced. The code is written in C and is distributed under the LGPLv2.1 license. More than 130 security issues have been resolved in VLC and its built-in libraries, related to buffer overflows, use-after-free memory access, integer overflows, and double free errors (details are not disclosed yet). Some vulnerabilities can be exploited when processing specially crafted content.

Among the changes unrelated to vulnerabilities and bug fixes:

  • Support for decoding Atrac3 and Atrac9 audio formats (Adaptive Transform Acoustic Coding) has been added.
  • A decoder for the APV (Advanced Professional Video) format has been added.
  • Support for CEA-708 subtitles in the MP4 multimedia container has been implemented.
  • Support for ID3v2 metadata has been added to the MPEG media container unpacker.
  • On the Windows platform, the ability to capture video in NV12 format using the DirectShow API has been implemented.
  • Support for connection request listening mode has been added to the SRT (Secure Reliable Transport) protocol implementation.
  • The logic for determining subtitle language from file names and SSA/ASS metadata has been improved.
  • Support for accessing content via SFTP protocol using public key authentication has been added.
  • The detection of SMB2 network shares has been improved.
  • Support for packaging in Flatpak format has been added.
  • NPAPI plugins and youtube.lua have been removed. The RealRTSP plugin build is disabled by default.
  • Transitioned to using a new RSA-4096 key for verifying updates.
  • 49 third-party libraries have been updated. The FFmpeg package has been upgraded from version 4.4 to 8.1.2.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster