Das VideoLAN Team gab eine neue Version des Mediaplayers VideoLAN frei. VLC 0.8.6h beseitigt vor allem Sicherheitslücken in den Bibliotheken GnuTLS, libgcrypt und libxml2 (Security Advisory SA0804 und SA0805).
Ebenfalls enthalten sind Stabilitäts-Updates für die Mac OS X Version sowie die Korrekturen des Quellcode-Releases VLC media player
0.8.6g; eine vollständige Liste der Veränderungen findet sich in den Changelogs für 0.8.6g und 0.8.6h.
Das Videolan-Team empfiehlt allen Benutzern, ihre Installation umgehend zu aktualisieren.
Neuerungen und Korrekturen
Security updates:
- Removed VLC variable settings from Mozilla and ActiveX (CVE-2007-6683, VideoLAN-SA-0804))
- Removed loading plugins from the current directory (CVE-2008-2147, VideoLAN-SA-0805))
- Updated libpng on Windows and Mac OS X (CVE-2008-1382)
- Fixed libid3tag denial of service (CVE-2008-2109)
- Fixed libvorbis vulnerabilities (CVE-2008-1419, CVE-2008-1420, CVE-2008-1423)
- Fixed speex insufficient boundary check (oCERT-2008-004)
Various bugfixes:
- Fixed various memory leaks, improving stability when running as a server
- Fixed compilation with recent versions of FFmpeg
- Correctly parses SAP announcements from MPEG-TS
- Fixed AAC resampling
- The Fullscreen Controller appears correctly on Mac OS X, if the 'Always-on-top' video option was selected.
Security updates
- Updated GnuTLS and libgcrypt on Windows and Mac OS X CVE-2008-1948, CVE-2008-1949, CVE-2008-1950
- Updated libxml2 on Windows and Mac OS X CVE-2007-6284
Goodies
- Updated libebml and libmatroska on Mac OS X. Reliability improvements.
- Miscellaneous bugfixes in multiple modules and in libvlc (ftp access, record access filter, video filters, RC interface, playlist demuxer, IP networking, MPJPEG muxer, stream outputs)
- Improved support for MPEG2 content created by Final Cut Pro
- More reliable audio reception for MPEG TS streams
- Fixed a regression in 0.8.6g where usage of the snapshot feature could lead to an unexpected application termination
- New Serbian translation
- Updated Romanian translation
Download
Binär-Pakete für MS Windows und Mac OS X stehen bereits zum Download zur Verfügung:
Andere Binär-Pakete für Debian GNU/Linux, Fedora Core, BeOS etc. sollen bald folgen.