• Skip to main content
  • Skip to header right navigation
  • Skip to site footer
iGuRu

iGuRu

Real-time Technology News. Opinions & Tweaks

  • / news
  • / infosec
  • / tools
  • / tweaks
  • / dummies
  • / opinions
  • / support
home / News / VLC: Doubts the existence of a security vacuum

VLC: Doubts the existence of a security vacuum

24/07/2019 07:46 by giorgos

Do you want to uninstall VLC? Many websites say that this is probably the best solution, but according to the developers of the application, the alleged security gap is excessive, and may not be dangerous at all.

The problem started with its publication CVE-2019-13615, characterized as a "critical" vulnerability with a score of 9,8 out of 10 (Heap Based Buffer Overflow Vulnerability).

VLC developers are unhappy that they did not even contact them before this bug was published.

This was probably not good. On the other hand, 9,8 out of 10 sounds like a nuclear disaster. This defect could lead to remote code execution, and they could gain control of your system through an error in VLC.

vlc - VLC: disputes the existence of a security gap

According to the CVE, this defect requires the reproduction of a defective MKV file. Theoretically, downloading a malicious MKV file from the Internet and running it could jeopardize VLC even though no one has yet reported that this has already happened. Also, the application version for macOS does not appear to be affected.

So, even if this defect is as bad as it sounds, you should be especially careful with MKV files. Do not download unreliable MKV files and do not run them with the popular application until an update is released.

But the update will probably be delayed, as the developers of the VLC application say no can reproduce the problem.

As the VLC developers explain in bug tracker of VideoLAN:


"We are sorry, but this error cannot be reproduced and does not crash VLC at all." - Jean-Baptiste Kempf

"If you read about the error in a news article claiming that there is a critical gap in VLC, I suggest you read the comment above first and review your (fake) news sources." - Francois Cartegnie

"It does not crash the regular version of VLC 3.0.7.1" - Jean-Baptiste Kempf.

We are waiting for the answer of the researchers who discovered the security gap. It will be interesting to see who is wrong.

VLC: Doubts the existence of a security vacuum was last modified: 24 July, 2019, 7: 46 am by giorgos

Subscribe to our newsletter

no spam

spread the news

  • Facebook
  • Twitter
  • Reddit
  • Printing
  • Email

Read them Technology News from all over the world, with the validity of iGuRu.gr

Follow us on Google News


Competition: Newstag: based, buffer, jean, jean-baptiste, VLC

You May Also Like

VLC Media Player 3.0.12.1 download the new version
Five free software to set a video as wallpaper in Windows 10
Hardcode subtitles on movie

About Us giorgos

George still wonders what he's doing here ...

Previous Post: « SmartScreen disable on Windows Edge 10 1903
Next Post: e cigarettes: China plans to take action »

Reader Interactions

Comment Policy:

IGuRu.gr does not publish the comments immediately. Malicious comments, comments that include ads, or comments that are offensive are deleted without notice. We do not adopt the opinions expressed by our readers.
Your comments will be displayed after approval by the administrators


Leave your comment
Ακύρωση απάντησης

Your email address is not published. Τα υποχρεωτικά πεδία σημειώνονται με *

 

 © 2021 · iGuRu.gr · ☢ · Keep It Simple Stupid Genesis theme

about  ·   get in touch  ·  rss  ·  sitemap  ·  cough

loadingCancel
Could not post post - check your email address!
Email verification failed, please try again
Your blog can not post posts via email.