-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-5545-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff November 02, 2023 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : vlc CVE ID : not yet available An out-of-bounds write was discovered in the MMS demuxer of the VLC media player. For the oldstable distribution (bullseye), this problem has been fixed in version 3.0.20-0+deb11u1. For the stable distribution (bookworm), this problem has been fixed in version 3.0.20-0+deb12u1. We recommend that you upgrade your vlc packages. For the detailed security status of vlc please refer to its security tracker page at: https://security-tracker.debian.org/tracker/vlc Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: debian-security-announce@lists.debian.org -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEtuYvPRKsOElcDakFEMKTtsN8TjYFAmVEH5kACgkQEMKTtsN8 TjYMow/+KOrk/MxdRYRFak834AI5p0eEiDJIJm9mdZmoW50O2w6ojYzhXMaMor91 FYcE7EqhwbxIUnXayeMkRYktH0ihPVQA6J/Gzn3IVGVRR9Qk/er1YjHmTgaGRz64 2138+QB3YoZuYYcbTOMDfKLihDRIjW9qt1SSJibOS5qXOlYQ/YTYdNSSUu4xt7at tLUDL/fYyuCiRGk9dkh0joc6UHzymufLHjN0YE63izBIx6LrygGLpueRqgGsphJG kf8KtZa7mE7aLidn/6RCEKf+egBvVukF7oFU9YrlNo2pChdpacB1f6Yj6p1kmHiM QifST6ZCVc+n4FkwpVfPMVxs/XWzuJDtqV6nOKQE0omNfbHDjYRykGkzWqIJVPl5 ysHSYGf00I0YO6eiA7oXkfv6QKItHw3XS1PtXczlJVJE7GkrO9h9n+tgaq50Qq9L 3dfHxHgifCLk6wkSls42GRpvpmChsI1rLNQBYE2+BqHeygeshmntJAjhZpKBSTIj dEJq2QdKW2S2YngN0FAdWvH1UhgtaZmiKCmflNbMij+4tuE09OGZyTyMcqZh0dt3 1S4jNLlzk5BqAjeEgkn/SJYFI5bhItHLnDsglJAsQHdFpRX2DObMZmmfRRVjFGSx a8aTO/mMpPzyg2IxQwt08XZlj5diO25Gtvdt8W17MCQ3W+Y7bEQ= =5Fzr -----END PGP SIGNATURE-----