-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-4366-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff January 12, 2019 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : vlc CVE ID : CVE-2018-19857 An integer underflow was discovered in the CAF demuxer of the VLC media player. For the stable distribution (stretch), this problem has been fixed in version 3.0.6-0+deb9u1. We recommend that you upgrade your vlc packages. For the detailed security status of vlc please refer to its security tracker page at: https://security-tracker.debian.org/tracker/vlc Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: debian-security-announce@lists.debian.org -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEtuYvPRKsOElcDakFEMKTtsN8TjYFAlw53uEACgkQEMKTtsN8 TjYgbA//codUcz9c+IhREMe5pF/dAe82Nhl3fjAZdy4SecsfP1etpF1R/unDVDT7 3X4qBZGUEyyKJX75MidhRHgqnKswpoBGtHeY62BmkLoMNP/yiZNdyT2dvoxcgT3L f9zBiPvkKnYzsOEAXTpeiTp+QUPBG/kaYrHEV2FKCSj5aYwLWdcU7/wjfNeTHcmM zkQLc0YsA9FJNTWoyC3DUm3gzIRc1qsQH2BHri1QZoiS7CQ2QHQYr+VATH6WxS4x ofqz91RyH49cw793WucifMxZf/2gqORiTPd6dd8S5PoTkMJglGb64Js6G0zLjup6 D2WoGIpsxVNPti8Z4t4qWMNH2fyGhlgA6brWOD/c011ANh+x8HrWkEaoCFC4K0sI Pn/Q1EZ5ya00sweef+y2Kg9O+xf2nw/iBpfRLW3pQN2Lu6s0TvrbS5IQD6McTtXb yIA64DfFFWgHzdjXiJPfU66/xTQBdyS9wBx51nheA41vStmAPQFXeRoFBWSrc8Yg ac5l4qJImQq6hL46d93HOgLGGg5iJ6O4/iE1uDs72JcruF/WJZ7OfW9ojSNymIRF XNibboQ9xfAGdrdmBpXk8fgJ1ag5L0Vp9CqgjR0HXa8/ONass72V4CM0JYgsqdXs Zo1qP1KCfkdq+o1zgi0/OiTrnRkbA8Dt9WSMOv5nlWT+Kz+zCAc=HPRG -----END PGP SIGNATURE-----