<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[[Solved] VLC 3.0.3 detected as safe]]></title><description><![CDATA[<p dir="auto">Hi,<br />
VLC 3.0.3 is known to haves security issues and replaced by 3.0.4.<br />
Regards.<br />
Greg.</p>
]]></description><link>https://vulndetect.org/topic/477/solved-vlc-3-0-3-detected-as-safe</link><generator>RSS for Node</generator><lastBuildDate>Sun, 07 Jun 2026 14:13:15 GMT</lastBuildDate><atom:link href="https://vulndetect.org/topic/477.rss" rel="self" type="application/rss+xml"/><pubDate>Sun, 25 Nov 2018 17:38:22 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to [Solved] VLC 3.0.3 detected as safe on Sun, 30 Dec 2018 09:50:24 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/gregalexandre" aria-label="Profile: GregAlexandre">@<bdi>GregAlexandre</bdi></a> OK, then I mark the topic as Solved</p>
]]></description><link>https://vulndetect.org/post/2314</link><guid isPermaLink="true">https://vulndetect.org/post/2314</guid><dc:creator><![CDATA[OLLI_S]]></dc:creator><pubDate>Sun, 30 Dec 2018 09:50:24 GMT</pubDate></item><item><title><![CDATA[Reply to [Solved] VLC 3.0.3 detected as safe on Sat, 29 Dec 2018 17:51:49 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/tom" aria-label="Profile: Tom">@<bdi>Tom</bdi></a><br />
From changelog 3.0.4 to 3.0.5<br />
"Update numerous 3rd party libraries, including for minor security issues"</p>
<p dir="auto">This subject could be close.</p>
<p dir="auto">Thanks a lot Tom.</p>
]]></description><link>https://vulndetect.org/post/2312</link><guid isPermaLink="true">https://vulndetect.org/post/2312</guid><dc:creator><![CDATA[GregAlexandre]]></dc:creator><pubDate>Sat, 29 Dec 2018 17:51:49 GMT</pubDate></item><item><title><![CDATA[Reply to [Solved] VLC 3.0.3 detected as safe on Fri, 28 Dec 2018 16:00:09 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/tom" aria-label="Profile: Tom">@<bdi>Tom</bdi></a> Thank you, I updated it yesterday ;-)</p>
]]></description><link>https://vulndetect.org/post/2308</link><guid isPermaLink="true">https://vulndetect.org/post/2308</guid><dc:creator><![CDATA[Anselm]]></dc:creator><pubDate>Fri, 28 Dec 2018 16:00:09 GMT</pubDate></item><item><title><![CDATA[Reply to [Solved] VLC 3.0.3 detected as safe on Fri, 28 Dec 2018 14:57:09 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/anselm" aria-label="Profile: Anselm">@<bdi>Anselm</bdi></a> VLC 3.0.5 is out</p>
]]></description><link>https://vulndetect.org/post/2305</link><guid isPermaLink="true">https://vulndetect.org/post/2305</guid><dc:creator><![CDATA[Tom]]></dc:creator><pubDate>Fri, 28 Dec 2018 14:57:09 GMT</pubDate></item><item><title><![CDATA[Reply to [Solved] VLC 3.0.3 detected as safe on Thu, 06 Dec 2018 09:30:14 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/anselm" aria-label="Profile: Anselm">@<bdi>Anselm</bdi></a> Correction: OK, i did not see it <strong>yesterday</strong> at <a href="http://cve.mitre.org" rel="nofollow ugc">cve.mitre.org</a> using the search. But now i knew why:<br />
Date Entry Created<br />
20181205</p>
]]></description><link>https://vulndetect.org/post/1930</link><guid isPermaLink="true">https://vulndetect.org/post/1930</guid><dc:creator><![CDATA[Anselm]]></dc:creator><pubDate>Thu, 06 Dec 2018 09:30:14 GMT</pubDate></item><item><title><![CDATA[Reply to [Solved] VLC 3.0.3 detected as safe on Thu, 06 Dec 2018 08:51:42 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/tom" aria-label="Profile: Tom">@<bdi>Tom</bdi></a> OK, i did not see it at <a href="http://cve.mitre.org" rel="nofollow ugc">cve.mitre.org</a> using the search.</p>
]]></description><link>https://vulndetect.org/post/1928</link><guid isPermaLink="true">https://vulndetect.org/post/1928</guid><dc:creator><![CDATA[Anselm]]></dc:creator><pubDate>Thu, 06 Dec 2018 08:51:42 GMT</pubDate></item><item><title><![CDATA[Reply to [Solved] VLC 3.0.3 detected as safe on Thu, 06 Dec 2018 08:48:11 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/anselm" aria-label="Profile: Anselm">@<bdi>Anselm</bdi></a> See this:<br />
<a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-19857" rel="nofollow ugc">https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-19857</a></p>
]]></description><link>https://vulndetect.org/post/1927</link><guid isPermaLink="true">https://vulndetect.org/post/1927</guid><dc:creator><![CDATA[Tom]]></dc:creator><pubDate>Thu, 06 Dec 2018 08:48:11 GMT</pubDate></item><item><title><![CDATA[Reply to [Solved] VLC 3.0.3 detected as safe on Wed, 05 Dec 2018 20:31:56 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/tom" aria-label="Profile: Tom">@<bdi>Tom</bdi></a> says, 3.0.2, 3.0.3, 3.0.4 are not insecure, but 3.0.4 is recommended . I only found an information, that 3.0.1 is insecure.</p>
]]></description><link>https://vulndetect.org/post/1918</link><guid isPermaLink="true">https://vulndetect.org/post/1918</guid><dc:creator><![CDATA[Anselm]]></dc:creator><pubDate>Wed, 05 Dec 2018 20:31:56 GMT</pubDate></item><item><title><![CDATA[Reply to [Solved] VLC 3.0.3 detected as safe on Wed, 05 Dec 2018 19:58:17 GMT]]></title><description><![CDATA[<p dir="auto">Tom, is the issue solved (after you flagged all versions as being "Insecure")?</p>
]]></description><link>https://vulndetect.org/post/1916</link><guid isPermaLink="true">https://vulndetect.org/post/1916</guid><dc:creator><![CDATA[OLLI_S]]></dc:creator><pubDate>Wed, 05 Dec 2018 19:58:17 GMT</pubDate></item><item><title><![CDATA[Reply to [Solved] VLC 3.0.3 detected as safe on Wed, 05 Dec 2018 13:11:28 GMT]]></title><description><![CDATA[<p dir="auto">:D</p>
<p dir="auto">Thank you.</p>
<p dir="auto">Yeah, well, as we discussed that, it seems that a guy has found a vuln in 3.0.4.</p>
<p dir="auto">So it is time to flag all versions as being "Insecure" :(</p>
<p dir="auto">Let's hope a new release of VLC comes out one of the next days.</p>
<p dir="auto">CVE Details is a great site for getting some high level information about the history of a product.</p>
<p dir="auto">However, CVE itself, has seen better days, unfortunately a lot of vulns are assigned CVEs rather late and a lot never receives a CVE.</p>
<p dir="auto">Just look at yesterdays Chrome release, where some of the vulns are "To be allocated [a CVE]". That seems odd for such a significant app as Chrome:<br />
<a href="https://chromereleases.googleblog.com/2018/12/stable-channel-update-for-desktop.html" rel="nofollow ugc">https://chromereleases.googleblog.com/2018/12/stable-channel-update-for-desktop.html</a></p>
]]></description><link>https://vulndetect.org/post/1909</link><guid isPermaLink="true">https://vulndetect.org/post/1909</guid><dc:creator><![CDATA[Tom]]></dc:creator><pubDate>Wed, 05 Dec 2018 13:11:28 GMT</pubDate></item><item><title><![CDATA[Reply to [Solved] VLC 3.0.3 detected as safe on Wed, 05 Dec 2018 11:07:04 GMT]]></title><description><![CDATA[<p dir="auto">FYI:<br />
Common Vulnerabilities and Exposures (CVE):</p>
<p dir="auto"><a href="https://www.cvedetails.com/version-list/5842/9978/1/Videolan-Vlc-Media-Player.html" rel="nofollow ugc">https://www.cvedetails.com/version-list/5842/9978/1/Videolan-Vlc-Media-Player.html</a></p>
<p dir="auto"><a href="https://www.cvedetails.com/product/9978/Videolan-Vlc-Media-Player.html?vendor_id=5842" rel="nofollow ugc">https://www.cvedetails.com/product/9978/Videolan-Vlc-Media-Player.html?vendor_id=5842</a></p>
<p dir="auto"><a href="https://cve.mitre.org/cgi-bin/cvekey.cgi?keyword=VLC" rel="nofollow ugc">https://cve.mitre.org/cgi-bin/cvekey.cgi?keyword=VLC</a></p>
]]></description><link>https://vulndetect.org/post/1908</link><guid isPermaLink="true">https://vulndetect.org/post/1908</guid><dc:creator><![CDATA[Anselm]]></dc:creator><pubDate>Wed, 05 Dec 2018 11:07:04 GMT</pubDate></item><item><title><![CDATA[Reply to [Solved] VLC 3.0.3 detected as safe on Tue, 04 Dec 2018 10:40:17 GMT]]></title><description><![CDATA[<p dir="auto">Unless some more tangible report comes out, then we will keep flagging 3.0.2, 3.0.3 and 3.0.4 as "OK", with 3.0.4 being the recommended version.</p>
<p dir="auto">But thank you for reporting this, in this time and age you can't just rely on vendors to report all issues, so when you see reports elsewhere, then please post here or send me a chat message and we will investigate.</p>
]]></description><link>https://vulndetect.org/post/1875</link><guid isPermaLink="true">https://vulndetect.org/post/1875</guid><dc:creator><![CDATA[Tom]]></dc:creator><pubDate>Tue, 04 Dec 2018 10:40:17 GMT</pubDate></item><item><title><![CDATA[Reply to [Solved] VLC 3.0.3 detected as safe on Sun, 02 Dec 2018 20:10:06 GMT]]></title><description><![CDATA[<p dir="auto">Maybe a copy paste error?</p>
<p dir="auto"><a href="https://portableapps.com/news/2018-09-01--vlc-media-player-portable-3.0.4-released" rel="nofollow ugc">https://portableapps.com/news/2018-09-01--vlc-media-player-portable-3.0.4-released</a> (This version fixes a critical security issue in VLC.)<br />
<a href="https://portableapps.com/news/2018-05-31--vlc-media-player-portable-3.0.3-released" rel="nofollow ugc">https://portableapps.com/news/2018-05-31--vlc-media-player-portable-3.0.3-released</a> ( This version fixes a critical security issue in VLC.)<br />
<a href="https://portableapps.com/news/2018-05-06--vlc-media-player-portable-3.0.2-released" rel="nofollow ugc">https://portableapps.com/news/2018-05-06--vlc-media-player-portable-3.0.2-released</a> (This version fixes a critical security issue in VLC. )<br />
<a href="https://portableapps.com/news/2018-03-21--vlc-media-player-portable-3.0.1-released" rel="nofollow ugc">https://portableapps.com/news/2018-03-21--vlc-media-player-portable-3.0.1-released</a> (This version fixes a critical security issue in VLC.)</p>
]]></description><link>https://vulndetect.org/post/1855</link><guid isPermaLink="true">https://vulndetect.org/post/1855</guid><dc:creator><![CDATA[Anselm]]></dc:creator><pubDate>Sun, 02 Dec 2018 20:10:06 GMT</pubDate></item><item><title><![CDATA[Reply to [Solved] VLC 3.0.3 detected as safe on Sun, 02 Dec 2018 19:13:15 GMT]]></title><description><![CDATA[<p dir="auto">Hi Tom,</p>
<p dir="auto">When I launched VLC  I got a message that a new version was available and fixing security issues. I patched, reported and did not look for anything else: as you pinpointed they are quite good for security and providing information.</p>
<p dir="auto">I remember that I was a bit surprised to have miss this in security bulletins that I receive: it seems that I was not so bad.:relaxed:</p>
<p dir="auto">I am not alone with this: <a href="https://portableapps.com/news/2018-09-01--vlc-media-player-portable-3.0.4-released" rel="nofollow ugc">https://portableapps.com/news/2018-09-01--vlc-media-player-portable-3.0.4-released</a></p>
<p dir="auto">I also found that (<a href="https://www.wilderssecurity.com/threads/vlc-3-0-vetinari-released.400558/page-3" rel="nofollow ugc">https://www.wilderssecurity.com/threads/vlc-3-0-vetinari-released.400558/page-3</a>):</p>
<p dir="auto">"The changelog for 3.0.4 doesn't mention security fixes specifically, but the release notes in the built-in updater do:<br />
VideoLAN and the VLC development team present VLC 3.0 "Vetinari".<br />
VLC 3.0.4 is a minor update to VLC 3.0 branch, fixes numerous hardware decoding issues, adds support for AV1 streams <strong>and fixes security issues</strong>. It also improves the support for numerous formats, and regressions in video quality compared to 2.2.x, in certain cases.""</p>
<p dir="auto">I am quite sure that I read this somewhere as I was surprised they let regressions and that I had (have) no idea of what is an "AV1 stream".</p>
<p dir="auto">Hope this helps.<br />
Regards.<br />
Greg.</p>
]]></description><link>https://vulndetect.org/post/1854</link><guid isPermaLink="true">https://vulndetect.org/post/1854</guid><dc:creator><![CDATA[GregAlexandre]]></dc:creator><pubDate>Sun, 02 Dec 2018 19:13:15 GMT</pubDate></item><item><title><![CDATA[Reply to [Solved] VLC 3.0.3 detected as safe on Tue, 27 Nov 2018 12:29:29 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/anselm" aria-label="Profile: Anselm">@<bdi>Anselm</bdi></a> Thank you</p>
]]></description><link>https://vulndetect.org/post/1790</link><guid isPermaLink="true">https://vulndetect.org/post/1790</guid><dc:creator><![CDATA[Tom]]></dc:creator><pubDate>Tue, 27 Nov 2018 12:29:29 GMT</pubDate></item><item><title><![CDATA[Reply to [Solved] VLC 3.0.3 detected as safe on Mon, 26 Nov 2018 22:07:49 GMT]]></title><description><![CDATA[<p dir="auto">FYI:<br />
<a href="https://www.videolan.org/security/" rel="nofollow ugc">https://www.videolan.org/security/</a> "... Please note: The VideoLAN project does not issue security advisories for underlying third party libraries. Please refer to the concerned third parties as appropriate. ..."</p>
<p dir="auto">BTW, there is a secuirty issue in LIVE555 media streaming library, but this should not influence vlc, see:</p>
<p dir="auto"><a href="https://www.hackread.com/watch-out-for-this-vulnerability-in-vlc-mplayer/" rel="nofollow ugc">https://www.hackread.com/watch-out-for-this-vulnerability-in-vlc-mplayer/</a> (October 20th, 2018)<br />
<a href="https://talosintelligence.com/vulnerability_reports/TALOS-2018-0684" rel="nofollow ugc">https://talosintelligence.com/vulnerability_reports/TALOS-2018-0684</a><br />
<a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-4013" rel="nofollow ugc">https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-4013</a></p>
]]></description><link>https://vulndetect.org/post/1789</link><guid isPermaLink="true">https://vulndetect.org/post/1789</guid><dc:creator><![CDATA[Anselm]]></dc:creator><pubDate>Mon, 26 Nov 2018 22:07:49 GMT</pubDate></item><item><title><![CDATA[Reply to [Solved] VLC 3.0.3 detected as safe on Mon, 26 Nov 2018 12:52:47 GMT]]></title><description><![CDATA[<p dir="auto">Hi Greg,</p>
<p dir="auto">3.0.4 has actually been out for a while, but when we added the rule it wasn't yet the recommended version - this I have updated now - thank you.</p>
<p dir="auto">Where did you get the information 3.0.3 is vulnerable?</p>
<p dir="auto">As you can see, there is (at the time of writing) no official information on the VLC site, and they are usually good at providing this information:<br />
<a href="https://www.videolan.org/news.html" rel="nofollow ugc">https://www.videolan.org/news.html</a><br />
<a href="https://www.videolan.org/security/" rel="nofollow ugc">https://www.videolan.org/security/</a></p>
<p dir="auto">/Tom</p>
]]></description><link>https://vulndetect.org/post/1787</link><guid isPermaLink="true">https://vulndetect.org/post/1787</guid><dc:creator><![CDATA[Tom]]></dc:creator><pubDate>Mon, 26 Nov 2018 12:52:47 GMT</pubDate></item></channel></rss>