• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Download VulnDetect Installer
  • Login
SecTeer VulnDetect & PatchPro Support Forum VulnDetect
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Download VulnDetect Installer
  • Login

[Solved] VLC 3.0.11 not detected as unsecure without available patch

Scheduled Pinned Locked Moved Solved Detection Issues
5 Posts 3 Posters 483 Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • G Offline
    GregAlexandre
    last edited by OLLI_S 16 Jan 2021, 11:34

    Hi,
    At this time (2021-01-16) VLC 3.0.11 is known to be unsecure without available patch: https://nvd.nist.gov/vuln/detail/CVE-2020-26664 .
    Vulndetect does not display it as unsecure and does not states that there is no available patch.

    Hope this helps.

    Regards.

    1 Reply Last reply Reply Quote 0
    • V Offline
      VulnDetect
      last edited by 17 Jan 2021, 17:21

      @GregAlexandre Thank you.

      It appears that they do have a fix in the pipeline:
      https://code.videolan.org/videolan/vlc-3.0/-/commit/ec1f55ee9ace5cc675395a1bc9700d99679e7e8c

      For some reason they haven't released 3.0.12 yet.

      We have flagged 3.0.11 as Insecure and will closely monitor the release of 3.0.12.

      /Tom

      1 Reply Last reply Reply Quote 0
      • V Offline
        VulnDetect
        last edited by 18 Jan 2021, 16:45

        Earlier today the installer for 3.0.12 was released, and short time ago the security page was updated. However, the actual VideoLAN advisory, is still 404.

        Anyway, the rule is updated and a package is available, and the first users and customers has applied the updated version.

        Again, thank you for reporting this.

        /Tom

        G 1 Reply Last reply 21 Jan 2021, 16:28 Reply Quote 0
        • G Offline
          GregAlexandre @VulnDetect
          last edited by 21 Jan 2021, 16:28

          @VulnDetect & @Tom & @OLLI_S : Fixed
          Can be moved to "solved issue".
          Thanks.

          1 Reply Last reply Reply Quote 0
          • O Offline
            OLLI_S Community Moderator
            last edited by 17 Feb 2021, 20:09

            OK, then I mark this issue as solved.

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Download SecTeer Personal VulnDetect - an alternative to the long lost Secunia PSI

            Please see our Privacy and Data Processing Policy
            Sponsored and operated by SecTeer | VulnDetect is a replacement for the EoL Secunia PSI
            Forum software by NodeBB