VLC²¥·ÅÆ÷¶à¸öÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2019-08-21

? Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-13602£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º8.8
CVE±àºÅ£ºCVE-2019-13962£¬Î£ÏÕ¼¶±ð£ºÑÏÖØ£¬CVSS·ÖÖµ£º9.8


Ó°Ïì°æ±¾


ÊÜÓ°ÏìµÄ°æ±¾


VLC 3.0.2 to 3.0.7.1


Îó²î¸ÅÊö


VideoLAN VLC media playerÊÇ·¨¹úVideoLAN×éÖ¯µÄÒ»¿îÃâ·Ñ¡¢¿ªÔ´µÄ¿çƽ̨¶àýÌå²¥·ÅÆ÷£¨Ò²ÊÇÒ»¸ö¶àýÌå¿ò¼Ü£©¡£¸Ã²úÆ·Ö§³Ö²¥·Å¶àÖÖ½éÖÊ£¨Îļþ¡¢¹âÅ̵ȣ©¡¢¶àÖÖÒôÊÓÆµÃûÌã¨WMV,MP3µÈ£©µÈ¡£


VLCÐû²¼Ð°汾ÐÞ¸´ÁË13¸öÇå¾²Îó²î£ºCVE-2019-13602£¬CVE-2019-13962£¬CVE-2019-14437£¬CVE-2019-14438£¬CVE-2019-14498£¬CVE-2019-14535£¬CVE-2019-14534£¬CVE-2019-14533£¬CVE-2019-14776£¬CVE-2019-14778£¬CVE-2019-14779£¬CVE-2019-14777£¬CVE-2019-14970¡£ÆäÖÐCVE-2019-13602ºÍCVE-2019-13962·ÖÊý»®·ÖΪ8.8ºÍ9.8£¬¸ÅÊöÈçÏ£º


CVE-2019-13602

VideoLAN VLC media playerÖеÄmodules/demux/mp4/mp4.cÎļþµÄ¡®MP4_EIA608_Convert()¡¯º¯Êý±£´æÊý×Ö¹ýʧÎó²î¡£¸ÃÎó²îÔ´ÓÚÍøÂçϵͳ»ò²úƷδ׼ȷÅÌËã»òת»»Ëù±¬·¢µÄÊý×Ö¡£¹¥»÷Õß¿ÉʹÓøÃÎó²îµ¼ÖÂÕûÊýÒç³ö»ò·ûºÅ¹ýʧµÈ¡£


CVE-2019-13962

VideoLAN VLC media playerÖеÄmodules/codec/avcodec/video.cÎļþµÄlavc_CopyPicture±£´æ»º³åÇø¹ýʧÎó²î¡£¸ÃÎó²îÔ´ÓÚÍøÂçϵͳ»ò²úÆ·ÔÚÄÚ´æÉÏÖ´ÐвÙ×÷ʱ£¬Î´×¼È·ÑéÖ¤Êý¾Ý½çÏߣ¬µ¼ÖÂÏò¹ØÁªµÄÆäËûÄÚ´æÎ»ÖÃÉÏÖ´ÐÐÁ˹ýʧµÄ¶Áд²Ù×÷¡£¹¥»÷Õß¿ÉʹÓøÃÎó²îµ¼Ö»º³åÇøÒç³ö»ò¶ÑÒç³öµÈ¡£


Îó²îÑéÖ¤


ÔÝÎÞPOC/EXP¡£


ÐÞ¸´½¨Òé


ÏÖÔÚ³§ÉÌÒÑÐû²¼3.0.8°æ±¾ÒÔÐÞ¸´Îó²î£¬ÏÂÔØÁ´½Ó£ºhttps://www.videolan.org/vlc/#download¡£


²Î¿¼Á´½Ó


https://www.videolan.org/security/sb-vlc308.html