• About
  • Advertise
  • Careers
  • Contact
Friday, March 31, 2023
No Result
View All Result
NEWSLETTER
Cyber360 News
  • Home
  • Security
  • Data Breach
  • Cyber Attacks
  • Cyber Security
  • Cyber Crime
  • Contact Us
  • Home
  • Security
  • Data Breach
  • Cyber Attacks
  • Cyber Security
  • Cyber Crime
  • Contact Us
No Result
View All Result
Cyber360 News
No Result
View All Result
Home Security

VLC Media Player Has Critical Security Flaw [Updated: Devs Deny All Claims]

by Cyber360 News
November 11, 2019
in Security
0
VLC Media Player Has Critical Security Flaw [Updated: Devs Deny All Claims]
0
SHARES
0
VIEWS
Share on FacebookShare on Twitter

Update

VideoLAN has tweeted that the security issue reported by CERT-Bund is not as severe as claimed. VideoLAN says the issue lies in a third-party library, called libebml, that was fixed 16 months ago. VLC makers say that the claim was based on a previous (and outdated) version of VLC. Meanwhile, the VLC CVE has now been updated. It says that the severity of the issue from a Base Score of 9.8 (critical) to 5.5 (medium). The changelog also makes it clear that the “Victim must voluntarily interact with attack mechanism.”

PS: VLC users don’t need to uninstall it to stay protected from the vulnerability. You just have to ensure that it is updated to the latest version.

Original story continues from here [Published on July 24, 2019]

jamf now

If you still use the popular open-source VLC Media Player, you might want to uninstall it (at least for now). German security agency CERT-Bund has discovered a critical security flaw in VLC that could be used by attackers for remote code execution or cause a DDoS.

The worst part is that VideoLAN (the team behind VLC) doesn’t have a complete patch at the moment and until it rolls out one, your PC remains vulnerable.

Vulnerability in VLC Media Player

The vulnerability, described in CVE-2019-13615, reads:

“A remote, anonymous attacker can exploit a vulnerability in VLC to execute arbitrary code, create a denial of service state, disclose information, or manipulate files.”

In short, this security flaw can allow hackers to hijack your PC and go through your files.

A fix on the way

Fortunately, there have been no reports of exploitation of this flaw. WinFuture reports that Windows, Linux, and Unix versions of VLC have been affected by the security hole, but the macOS version remains safe.

Nevertheless, it totals up to a huge number of potentially vulnerable systems out there.

VideoLAN has been informed of the issue and the team is currently working on a patch. However, the patch is nearly 60% complete. We will have to wait longer for a fix.

jamf now
Also Read: 8 Chrome & Firefox Extensions Stole 4 Million Users’ Data: Uninstall Now!
Cyber360 News

Cyber360 News

Next Post
Latest Versions of Windows 10 Are More Secure Against Zero-Day Attacks

Latest Versions of Windows 10 Are More Secure Against Zero-Day Attacks

Recent Posts

Twitch’s Entire Critical Data Leaked, Includes Streamer Earnings, Source Code

Twitch’s Entire Critical Data Leaked, Includes Streamer Earnings, Source Code

October 6, 2021
Former U.S. Security Firm Helped The UAE Carry Out “Karma” iMessage Hack: MIT Tech Review

Former U.S. Security Firm Helped The UAE Carry Out “Karma” iMessage Hack: MIT Tech Review

October 1, 2021
Facing “This App Has Been Blocked For Your Protection” Issue? Here’s How You Can Fix It

Facing “This App Has Been Blocked For Your Protection” Issue? Here’s How You Can Fix It

October 1, 2021

Whats New in Kali Linux?

September 14, 2021

Kali Linux 2019.3 Release (CloudFlare, Kali-status, metapackages, Helper-Scripts & LXD)

September 14, 2021

Kali Linux 2021.3 Release (OpenSSL, Kali-Tools, Kali Live VM Support, Kali NetHunter Smartwatch)

September 14, 2021

Kali Linux 2018.4 Release

September 14, 2021

Kali Linux 1.0.5 and Software Defined Radio

September 14, 2021

Kali Tools Website Launched, 1.0.9 Release

September 14, 2021

Kali Linux Dojo at Black Hat Vegas 2016

September 14, 2021

Category

Site Links

  • Log in
  • Entries feed
  • Comments feed
  • WordPress.org

About Us

We bring you the best Premium WordPress Themes that perfect for news, magazine, personal blog, etc. Check our landing page for details.

© 2019 Cyber360 News - Powered by WebSensePro

No Result
View All Result
  • Home
  • Security
  • Data Breach
  • Cyber Attacks
  • Cyber Security
  • Cyber Crime
  • Contact Us

© 2019 Cyber360 News - Powered by WebSensePro

Login to your account below

Forgotten Password?

Fill the forms bellow to register

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In