mercoledì 30 aprile 2025 19:15mobile   |   3dfxzone.it   |   amdzone.it   |   atizone.it   |   forumzone.it   |   hwsetup.it   |   nvidiazone.it   |   unixzone.it 
  ATIZONE.IT
  proudly powered by 3dfxzone.it
Home    |    News    |    Headlines    |    Articoli    |    Download    |    Community    |    Condividi    |    Contatti    |    Tag    |    Ricerca    |    Sitemap
 
Pubblicità Informazioni e Release Notes del file: VLC Media Player 3.0.7 Ultime News
Condividi su Facebook Condividi su Twitter Condividi su WhatsApp Condividi su reddit

We just released VLC 3.0.7, a minor update of VLC branch 3.0.x. This release is a bit special, because it has more security issues fixed than any other version of VLC.

This high number of security issues is due to the sponsoring of a bug bounty program funded by the European Commission, during the FOSSA program.

Severity

According to our scale, we have had 33 valid security issues fixed thanks to this program:

  • 2 high security issues, (only one was present in 3.0.x),
  • 21 medium security issues,
  • 20 low security issues.

The 2 more important issues are an Out-of-Bound Write and a Stack Buffer Overflow.

the Out-of-Bound Write is not in the VLC codebase, but in a dependency of VLC, the faad2 library, unmaintained, unfortunately.

the Stack Buffer Overflow is a VLC 4.0-only issue in the new RIST module, and is therefore not impacting actual release of VLC.

The medium security issues are mostly out-of-band reads, heap overflows, NULL-dereference and use-after-free security issues. Those issues should not be exploitable with ASLR, but are important anyway, because they can crash VLC.

The low security issues are mostly integer overflow, division by zero, and other out-of-band reads with no actual impact. Those issues are not exploitable.

30.04.2025  
Gaming & Retrogaming Utilities: MAME (Multiple Arcade Machine Emulator) 0.277
OpenGL & Vulkan Information Tools: GLview (ex OpenGL Extensions Viewer) 7.3.11
WinToUSB Free 9.8 consente di installare Windows su un drive USB esterno
29.04.2025  
GeForce & Radeon - Tuning & Monitoring Tools: ASUS GPU Tweak III 1.9.4.3
The Linux Kernel Organization rilascia il Linux Kernel 6.15-rc4: info e download
FastStone Image Viewer 8.0 Portable visualizza e modifica le immagini e le foto
Free Antivirus & Antimalware Utilities: Trellix Stinger 13.0.0.345 [Portable]
28.04.2025  
Le capacità dei frame buffer delle GeForce RTX 5080 SUPER e RTX 5070 SUPER
Cloud Computing & Backup Utilities: Microsoft OneDrive 25.060.0330.0003
27.04.2025  
Intel sceglie il nodo N2 di TSMC per la produzione dei processori Nova Lake
On line una foto del SoC ARM Tegra 239 di NVIDIA per la Switch 2 di Nintendo?
Original Xbox Emulator: xemu 0.8.56 è free e Open Source - Windows/macOS/Linux
HFS - HTTP File Server 0.57.0 consente di realizzare un server HTTP a costo zero
26.04.2025  
Free CyberSecurity & Privacy & Internet Monitoring Tools: Fort Firewall 3.17.4
AMD rilascia Ryzen Chipset Driver 7.04.09.545 per Windows 10 e Windows 11
25.04.2025  
Svelata la data di lancio dell'attesa scheda video GeForce RTX 5060 di NVIDIA
XMedia Recode 3.6.1.0 converte i contenti audio e video in qualsiasi formato
The Linux Kernel Organization rilascia il Linux Kernel 6.14.4: info e download
24.04.2025  
K-Lite Codec Tweak Tool 6.7.5 configura i codec audio e video di Windows
Free RAM Information Utilities: RAMMon 3.4 build 1000 - SDRAM DDR5 Ready
Indice delle news 
Ultimi File
GLview (ex OpenGL Extensions Viewer) 7.3.11
ASUS GPU Tweak III 1.9.4.3
Marathon | Gameplay Reveal Trailer
Marathon | Screenshots 4K
Marathon | Gameplay Overview Trailer
GPU-Z 2.65.1
GPU Caps Viewer 1.64
Painkiller (2025) Screenshot
Painkiller - Announcement Trailer
GPU Shark 2.7.0
Indice dei file 
3dfxzone.it   ][   amdzone.it   ][   atizone.it   ][   forumzone.it   ][   hwsetup.it   ][   nvidiazone.it   ][   unixzone.it   ][   links   ][   feed rss   ][   chi siamo   ][   sitemap
ATIZone.it è servito da una applicazione proprietaria di cui è vietata la riproduzione parziale o totale (layout e/o logica). I marchi e le sigle in esso citate sono proprietà degli aventi diritto. Note Legali. Privacy.