MGASA-2020-0203

Source
https://advisories.mageia.org/MGASA-2020-0203.html
Import Source
https://advisories.mageia.org/MGASA-2020-0203.json
JSON Data
https://api.test.osv.dev/v1/vulns/MGASA-2020-0203
Related
Published
2020-05-08T10:57:54Z
Modified
2020-05-08T10:23:21Z
Summary
Updated vlc packages fix security vulnerabilities
Details

Multiple security issues were discovered in the microdns plugin of the VLC media player, which could result in denial of service or potentially the execution of arbitrary code via malicious mDNS packets (CVE-2020-6071, CVE-2020-6072, CVE-2020-6073, CVE-2020-6077, CVE-2020-6078, CVE-2020-6079, CVE-2020-6080).

VLC has been updated to 3.0.10 to fix theese and other issues.

References
Credits

Affected packages

Mageia:7 / vlc

Package

Name
vlc
Purl
pkg:rpm/mageia/vlc?distro=mageia-7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.0.10-1.mga7

Ecosystem specific

{
    "section": "core"
}

Mageia:7 / vlc

Package

Name
vlc
Purl
pkg:rpm/mageia/vlc?distro=mageia-7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.0.10-1.mga7.tainted

Ecosystem specific

{
    "section": "tainted"
}