Inguqulelo entsha yeVLC 3.0.8 ifika nesisombululo seengxaki ezahlukeneyo zokhuseleko

Kwiintsuku ezithile ezidlulileyo Inguqulelo entsha yaziswa ukulungiswa komdlali weendaba odumileyo IVLC 3.0.8, apho ku Iibugs eziqokelelweyo zilungisiwe kwaye i-13 sesichengeni esisigxina

Zeziphi iingxaki ezintathu (CVE-2019-14970, CVE-2019-14777, CVE-2019-14533) kunokukhokelela ekuphunyezweni kwekhowudi yomhlaseli xa uzama ukudlala iifayile zemultimedia eyilelwe ngokukodwa iifomathi zeMKV kunye ne-ASF (ukurekhoda ukugcwala kwesikhuseli kunye neengxaki ezimbini zokufikelela kwimemori emva kokuyikhulula).

Ngakolunye uhlangothi Ubuthathaka obune kwiifomathi zokuqhuba I-OGG, i-AV1, i-FAAD, i-ASF zibangelwa kukwazi ukufunda idatha kwiindawo ezinememori ngaphandle kwesikhuseli esabiweyo.

Iingxaki ezintathu zikhokelela ekuchazeni isalathiso se-NULL kwi-dvdnav, ASF kunye nefomathi ye-AVI. Ukuba semngciphekweni kuvumela ukuphuphuma kwenamba kwi-MP4 unpacker.

Malunga nokuba semngciphekweni okungagungqiyo

Abaphuhlisi beVLC baqaphela ukuba ingxaki kwifomathi ye-OGG (I-CVE-2019-14438) ibifunda kwindawo engaphandle kwebala (funda i-buffer overflow), kodwa abaphandi bezokhuseleko Ndifumene ibango lokuba sesichengeni sokuba kunokwenzeka ukuba kubangele ukugcwala kokubhala kwaye uququzelele ukwenziwa kwekhowudi xa kusenziwa ii-OGG, i-OGM, kunye neefayile ze-OPUS ezinebhloko yentloko eyakhiwe ngokukodwa.

Kukwakho nokuba sesichengeni (I-CVE-2019-14533) kwifomathi ye-ASF, evumela ukuba ubhale idatha kwindawo yememori esele ikhululiwe kunye nokufezekisa ikhowudi ngokuskena phambili okanye ngasemva kumda wexesha ngelixa udlala iifayile zeWMV kunye neWMA.

Ukongeza, imiba ye-CVE-2019-13602 (ukuphuphuma okupheleleyo) kunye ne-CVE-2019-13962 (ukufundwa kwindawo engaphandle kwe-buffer) yabelwa inqanaba eliyingozi (8.8 kunye ne-9.8), kodwa abaphuhlisi beVLC abavumi ukuba obu buthathaka abunabungozi (cebisa ukutshintsha inqanaba liye ku-4.3).

Ukulungiswa okungakhuselekanga kubandakanya ukususa ukuthintitha xa ubukele iividiyo ngenqanaba lesakhelo esisezantsi, ukuphucula inkxaso yokusasaza okulungelelanisiweyo (ikhowudi yokuphucula i-buffering).

Bakwanceda ukusombulula iingxaki ngokunikezelwa kwemibhalo engezantsi yeWebVTT, ukuphucula ukukhutshwa komsindo kumaqonga e-macOS kunye ne-iOS.

Iskripthi sokukhuphela kwiYouTube sibuye sahlaziywa, sisombulula iingxaki ngokusetyenziswa kweDirect3D11 ukusebenzisa ukukhawulezisa izixhobo kwiinkqubo ezinabaqhubi abathile be-AMD.

Uyifaka njani iVLC Media Player 3.0.8 kwiLinux?

Kulabo ba I-Debian, Ubuntu, iLinux Mint kunye nabasebenzisi abavela, chwetheza oku kulandelayo kwisiphelo sendlela:

Sudo apt-fumana uhlaziyo lwe-sudo apt-fumana ukufaka i-vlc isikhangeli-iplagi-vlc

Ngelixa le- Abo bangabasebenzisi beArch Linux, iManjaro, Arco Linux okanye naluphi na ulwabiwo oluvela kwiArch Linux, kufuneka sichwetheze:

Isudo pacman -S vlc

Ukuba ungumsebenzisi wokusasazwa kwe-KaOS Linux, umyalelo wokufaka uyafana neArch Linux.

Ngoku kwabo abasebenzisi bayo nayiphi na inguqulelo evulekileyoSUSE, kufuneka uchwetheze kuphela kwisiphelo sendlela okulandelayo ukuze ufake:

I-sudo zypper ifaka i-vlc

Kulungiselelwe abo Abasebenzisi beFedora kunye nayiphi na into evela kuyo, kufuneka bathayiphe oku kulandelayo:

Sudo dnf faka i-https: //download1.rpmfusion.org/free/fedora/rpmfusion-free-release-$ (rpm -E% fedora) .noarch.rpm sudo dnf faka i-vlc

ukuba Zonke ezinye izabelo zeLinux, singayifaka le software ngoncedo lwePlppak okanye iiphakheji ze-Snap. Kuphela kufuneka sibe nenkxaso yokufaka usetyenziso lwezi teknoloji.

Si Ndifuna ukufaka ngoncedo lwe-Snap, kufuneka sichwetheze lo myalelo ulandelayo kwisiphelo sendlela:

Sudo snap faka i-vlc

Ukufakela ingxelo yenkqubo yomgqatswa, yenze ngo:

I-sudo snap faka i-vlc -candidate

Okokugqibela, ukuba ufuna ukufaka uhlobo lwe-beta yenkqubo kufuneka uchwetheze:

Sudo snap faka i-vlc -beta

Ukuba ufake usetyenziso kwi-Snap kwaye ufuna ukuvuselela kuhlobo olutsha, kuya kufuneka uchwetheze:

Sudo snap uhlaziye i-vlc

Okokugqibela ngo-qAbo bafuna ukufaka kwiPlppak, yenze ngalo myalelo ulandelayo:

flatpak fakela -user https://flathub.org/repo/appstream/org.videolan.VLC.flatpakref

Kwaye ukuba sele beyifakile kwaye bafuna ukuyihlaziya kufuneka bathayiphe:

flatpak -uhlaziyo lomsebenzisi org.videolan.VLC

Shiya uluvo lwakho

Idilesi yakho ye email aziyi kupapashwa. ezidingekayo ziphawulwe *

*

*

  1. Uxanduva lwedatha: UMiguel Ángel Gatón
  2. Injongo yedatha: Ulawulo lwe-SPAM, ulawulo lwezimvo.
  3. Umthetho: Imvume yakho
  4. Unxibelelwano lwedatha: Idatha ayizukuhanjiswa kubantu besithathu ngaphandle koxanduva lomthetho.
  5. Ukugcinwa kweenkcukacha
  6. Amalungelo: Ngalo naliphi na ixesha unganciphisa, uphinde uphinde ucime ulwazi lwakho.