Multiple vulnerabilities have been discovered in the Xen hypervisor:
More info:
https://www.debian.org/security/2018/dsa-4201
https://wpvulndb.com/vulnerabilities/9085
More info:
https://wpvulndb.com/vulnerabilities/9085
Hans Jerry Illikainen discovered a type conversion vulnerability in theMP4 demuxer of the VLC media player, which could result in the executionof arbitrary code if a malformed media file is played.
More info:
https://www.debian.org/security/2018/dsa-4203
OSS-fuzz, assisted by Max Dymond, discovered that cURL, an URL transferlibrary, could be tricked into reading data beyond the end of a heapbased buffer when parsing invalid headers in an RTSP response.
More info:
https://www.debian.org/security/2018/dsa-4202
https://wpvulndb.com/vulnerabilities/9084
More info:
https://wpvulndb.com/vulnerabilities/9084