DSA-4203 vlc – security update

Hans Jerry Illikainen discovered a type conversion vulnerability in theMP4 demuxer of the VLC media player, which could result in the executionof arbitrary code if a malformed media file is played. More info: https://www.debian.org/security/2018/dsa-4203

DSA-4202 curl – security update

OSS-fuzz, assisted by Max Dymond, discovered that cURL, an URL transferlibrary, could be tricked into reading data beyond the end of a heapbased buffer when parsing invalid headers in an RTSP response. More info: https://www.debian.org/security/2018/dsa-4202
Translate »