-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-4203-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff May 17, 2018 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : vlc CVE ID : CVE-2017-17670 Hans Jerry Illikainen discovered a type conversion vulnerability in the MP4 demuxer of the VLC media player, which could result in the execution of arbitrary code if a malformed media file is played. This update upgrades VLC in stretch to the new 3.x release series (as security fixes couldn't be sensibly backported to the 2.x series). In addition two packages needed to be rebuild to ensure compatibility with VLC 3; phonon-backend-vlc (0.9.0-2+deb9u1) and goldencheetah (4.0.0~DEV1607-2+deb9u1). VLC in jessie cannot be migrated to version 3 due to incompatible library changes with reverse dependencies and is thus now declared end-of-life for jessie. We recommend to upgrade to stretch or pick a different media player if that's not an option. For the stable distribution (stretch), this problem has been fixed in version 3.0.2-0+deb9u1. We recommend that you upgrade your vlc packages. For the detailed security status of vlc please refer to its security tracker page at: https://security-tracker.debian.org/tracker/vlc Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: debian-security-announce@lists.debian.org -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEtuYvPRKsOElcDakFEMKTtsN8TjYFAlr9nlUACgkQEMKTtsN8 Tjb5rw/+OncZS6nB0uDqmA0RcZugqvskqQReQbBqImwSSEzn2u9JY6wgi/Rmiuvr N+wsrXTw9ws2yewMah9Yy+K0+Ucq0+Hl+pPtjaSFhC8RKaYXZaS3GsdxutWuLxgz WtRPIU3o4+PP8fssR9P7uHRYESmT2+sccIB55vBj9TvLzZhgQJz4sniowbJ7en96 lVTBFpBesXXmijbLcabLSOzGDQ5qVcN5P4f+Alng+D5b1buIw75Efw70S9HCYX8H YexCfzOxEqcBxV3UNaUWPSXD/OCXt8cGxLzuQa03YhgDJLlasuXYJifPq8bffBkB UhE9yhDs9eZFyUMgZZ7dQVl6fO1/qKYBW4nTNAc2MTyPL+8olO2fSdA4nG4hDR8i HJC8E+vyWrbzYIivDEuDQats6e24R1wXrCdo1TG11R6iY7t1Mqg7paufK2oOOWbr XRF6rkpWhlfo3EJoU2dqxs90/LHnPaAM89GPkNBftmDrBKYKw3QhiULp2t6Ob9rk FTkycbZrGFKDTeacLfCZ6JnqrKHQC8F0M5JvV19ff1NU6SvpRWHxPQC3C/22u1L0 rjWPE0nLimyQ2QnHn8/hNp6sK0iEAGrl+XLPrw+dewsObq+UCDgHuyHJfYJnX2hx IGvl7VddHx5kBD78rL1ODMVmWIRHavt193u7/jfUKT+2PxOUwnY= =a0n7 -----END PGP SIGNATURE-----