Debian DSA-4203-1 : vlc - security update

high Nessus Plugin ID 109902

Synopsis

The remote Debian host is missing a security-related update.

Description

Hans Jerry Illikainen discovered a type conversion vulnerability in the MP4 demuxer of the VLC media player, which could result in the execution of arbitrary code if a malformed media file is played.

This update upgrades VLC in stretch to the new 3.x release series (as security fixes couldn't be sensibly backported to the 2.x series). In addition two packages needed to be rebuild to ensure compatibility with VLC 3; phonon-backend-vlc (0.9.0-2+deb9u1) and goldencheetah (4.0.0~DEV1607-2+deb9u1).

VLC in jessie cannot be migrated to version 3 due to incompatible library changes with reverse dependencies and is thus now declared end-of-life for jessie. We recommend to upgrade to stretch or pick a different media player if that's not an option.

Solution

Upgrade the vlc packages.

For the stable distribution (stretch), this problem has been fixed in version 3.0.2-0+deb9u1.

See Also

https://security-tracker.debian.org/tracker/source-package/vlc

https://packages.debian.org/source/stretch/vlc

https://www.debian.org/security/2018/dsa-4203

Plugin Details

Severity: High

ID: 109902

File Name: debian_DSA-4203.nasl

Version: 1.4

Type: local

Agent: unix

Published: 5/18/2018

Updated: 11/13/2018

Supported Sensors: Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 6.7

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P

CVSS v3

Risk Factor: High

Base Score: 8.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Vulnerability Information

CPE: p-cpe:/a:debian:debian_linux:vlc, cpe:/o:debian:debian_linux:9.0

Required KB Items: Host/local_checks_enabled, Host/Debian/release, Host/Debian/dpkg-l

Patch Publication Date: 5/17/2018

Reference Information

CVE: CVE-2017-17670

DSA: 4203