{"schema_version":"1.7.3","id":"openSUSE-SU-2023:0366-1","published":"2023-11-12T13:01:02Z","modified":"2026-02-04T03:47:20.787157Z","related":["CVE-2022-37434","CVE-2022-41325","CVE-2023-5217"],"upstream":["CVE-2022-37434","CVE-2022-41325","CVE-2023-5217"],"summary":"Security update for vlc","details":"This update for vlc fixes the following issues:\n\nUpdate to version 3.0.20:\n\n+ Video Output:\n  - Fix green line in fullscreen in D3D11 video output\n  - Fix crash with some AMD drivers old versions\n  - Fix events propagation issue when double-clicking with mouse wheel\n+ Decoders:\n  - Fix crash when AV1 hardware decoder fails\n+ Interface:\n  - Fix annoying disappearance of the Windows fullscreen controller\n+ Demuxers:\n  - Fix potential security issue (OOB Write) on MMS:// by checking user size bounds\n\nUpdate to version 3.0.19:\n\n+ Core: \n  - Fix next-frame freezing in most scenarios\n+ Demux: \n  - Support RIFF INFO tags for Wav files\n  - Fix AVI files with flipped RAW video planes\n  - Fix duration on short and small Ogg/Opus files\n  - Fix some HLS/TS streams with ID3 prefix\n  - Fix some HLS playlist refresh drift\n  - Fix for GoPro MAX spatial metadata\n  - Improve FFmpeg-muxed MP4 chapters handling\n  - Improve playback for QNap-produced AVI files\n  - Improve playback of some old RealVideo files\n  - Fix duration probing on some MP4 with missing information\n+ Decoders:\n  - Multiple fixes on AAC handling\n  - Activate hardware decoding of AV1 on Windows (DxVA)\n  - Improve AV1 HDR support with software decoding\n  - Fix some AV1 GBRP streams, AV1 super-resolution streams and monochrome ones\n  - Fix black screen on poorly edited MP4 files on Android Mediacodec\n  - Fix rawvid video in NV12\n  - Fix several issues on Windows hardware decoding (including 'too large resolution in DxVA')\n  - Improve crunchyroll-produced SSA rendering\n+ Video Output:\n  - Super Resolution scaling with nVidia and Intel GPUs\n  - Fix for an issue when cropping on Direct3D9\n  - Multiple fixes for hardware decoding on D3D11 and OpenGL interop\n  - Fix an issue when playing -90�rotated video\n  - Fix subtitles rendering blur on recent macOS\n+ Input:\n  - Improve SMB compatibility with Windows 11 hosts\n+ Contribs:\n  - Update of fluidlite, fixing some MIDI rendering on Windows\n  - Update of zlib to 1.2.13 (CVE-2022-37434)\n  - Update of FFmpeg, vpx (CVE-2023-5217), ebml, dav1d, libass\n+ Misc:\n  - Improve muxing timestamps in a few formats (reset to 0)\n  - Fix some rendering issues on Linux with the fullscreen controller\n  - Fix GOOM visualization\n  - Fixes for Youtube playback\n  - Fix some MPRIS inconsistencies that broke some OS widgets on Linux\n  - Implement MPRIS TrackList signals\n  - Fix opening files in read-only mode\n  - Fix password search using the Kwallet backend\n  - Fix some crashes on macOS when switching application\n  - Fix 5.1/7.1 output on macOS and tvOS\n  - Fix several crashes and bugs in the macOS preferences panel\n  - Improvements on the threading of the MMDevice audio output on Windows\n  - Fix a potential security issue on the uninstaller DLLs\n  - Fix memory leaks when using the media_list_player libVLC APIs\n+ Translations:\n  - Update of most translations\n  - New translations to Esperanto, Interlingue, Lao, Macedonian, Burmese, Odia, Samoan and Swahili\n","affected":[{"package":{"name":"vlc","ecosystem":"SUSE:Package Hub 15 SP5","purl":"pkg:rpm/suse/vlc&distro=SUSE%20Package%20Hub%2015%20SP5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.0.20-bp155.2.3.1"}]}],"ecosystem_specific":{"binaries":[{"libvlc5":"3.0.20-bp155.2.3.1","libvlccore9":"3.0.20-bp155.2.3.1","vlc":"3.0.20-bp155.2.3.1","vlc-codec-gstreamer":"3.0.20-bp155.2.3.1","vlc-devel":"3.0.20-bp155.2.3.1","vlc-jack":"3.0.20-bp155.2.3.1","vlc-lang":"3.0.20-bp155.2.3.1","vlc-noX":"3.0.20-bp155.2.3.1","vlc-opencv":"3.0.20-bp155.2.3.1","vlc-qt":"3.0.20-bp155.2.3.1","vlc-vdpau":"3.0.20-bp155.2.3.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2023:0366-1.json"}},{"package":{"name":"vlc","ecosystem":"openSUSE:Leap 15.5","purl":"pkg:rpm/opensuse/vlc&distro=openSUSE%20Leap%2015.5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.0.20-bp155.2.3.1"}]}],"ecosystem_specific":{"binaries":[{"libvlc5":"3.0.20-bp155.2.3.1","libvlccore9":"3.0.20-bp155.2.3.1","vlc":"3.0.20-bp155.2.3.1","vlc-codec-gstreamer":"3.0.20-bp155.2.3.1","vlc-devel":"3.0.20-bp155.2.3.1","vlc-jack":"3.0.20-bp155.2.3.1","vlc-lang":"3.0.20-bp155.2.3.1","vlc-noX":"3.0.20-bp155.2.3.1","vlc-opencv":"3.0.20-bp155.2.3.1","vlc-qt":"3.0.20-bp155.2.3.1","vlc-vdpau":"3.0.20-bp155.2.3.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2023:0366-1.json"}}],"references":[{"type":"ADVISORY","url":"https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/M45KVAFI32X55HONDKLE2FBN6GETMIUL/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1206142"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-37434"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-41325"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-5217"}]}