ubuntu 卸载vlc_否,您不需要卸载VLC

ubuntu 卸载vlc_否,您不需要卸载VLC_第1张图片

ubuntu 卸载vlc

ubuntu 卸载vlc_否,您不需要卸载VLC_第2张图片

“The sky is falling; uninstall VLC right now!” That’s the advice some websites are providing. But the purported VLC flaw is overblown—and, according to VLC’s developers, may not even be a real risk.

“天塌下来; 立即卸载VLC!” 这就是某些网站提供的建议。 但是声称的VLC缺陷被夸大了,而且据VLC的开发人员说,它甚至可能不是真正的风险。

This commotion all started with the publication of CVE-2019-13615, which is marked as a “critical” vulnerability with a score of 9.8 out of 10. VLC’s developers aren’t happy they weren’t even contacted before the publishing of this flaw.

这次骚动全部始于CVE-2019-13615的发布,该漏洞被标记为“严重”漏洞,满分为10,满分为9.8。VLC的开发人员不高兴他们甚至在发布此漏洞之前都没有被联系到。

Hey @MITREcorp and @CVEnew , the fact that you NEVER ever contact us for VLC vulnerabilities for years before publishing is really not cool; but at least you could check your info or check yourself before sending 9.8 CVSS vulnerability publicly…

嘿@MITREcorp和@CVEnew ,您在发布之前多年都从未联系过我们有关VLC漏洞的事实真的很酷; 但至少您可以在公开发送9.8 CVSS漏洞之前检查您的信息或检查自己…

— VideoLAN (@videolan) July 23, 2019

— VideoLAN(@videolan) 2019年7月23日

But it’s bad, right? That’s 9.8 out of 10—as security flaws go, it sounds like an incoming nuclear strike. This flaw could reportedly result in remote code execution, which is bad. Attackers could gain control of your system through a bug in VLC.

但这很不好,对吗? 十分之九(9.8)–随着安全漏洞的消失,这听起来像是即将来临的核打击。 据报道,此缺陷可能导致远程执行代码,这很糟糕。 攻击者可以通过VLC中的错误来控制您的系统。

As the CVE explains, this flaw requires playing a malformed MKV file. In theory, if you download a malicious MKV file from the web and run it, it could compromise VLC—although no one claims this has ever happened in the real world. Also, the macOS version of VLC doesn’t seem to be affected.

正如CVE所解释的,此缺陷需要播放格式错误的MKV文件。 从理论上讲,如果您从网络上下载恶意MKV文件并运行它,它可能会危害VLC-尽管没有人声称这在现实世界中曾经发生过。 此外,macOS版本的VLC似乎没有受到影响。

So, even if this flaw is as bad is it appears, you just have to be careful about MKV files—don’t download untrusted MKV files and play them in VLC until a patch is released. Stay away from MKV if you’re pirating media.

因此,即使此缺陷看上去很严重,您也必须注意MKV文件-在发布补丁之前,请不要下载不受信任的MKV文件并在VLC中播放它们。 如果您要盗版媒体,请远离MKV。

But not so fast! VLC’s developers say they can’t even reproduce the issue, suggesting that there are serious problems with the original exploit report.

但是没有那么快! VLC的开发人员说,他们甚至无法重现该问题,这表明原始漏洞利用报告存在严重问题。

Did you even check this?No one can reproduce this issue here.

您甚至检查了这个吗?没人可以在这里重现此问题。

— VideoLAN (@videolan) July 23, 2019

— VideoLAN(@videolan) 2019年7月23日

At the end of the day, it’s probably a good idea to stay away from downloaded MKV files until VLC patches this flaw. But that’s all you would really need to do, and even that’s being kind of paranoid.

归根结底,在VLC修复此漏洞之前,最好不要下载MKV文件。 但这就是您真正需要做的,即使那样也有点偏执。

As VLC’s developers explain on the VideoLAN bug tracker:

正如VLC的开发人员在VideoLAN错误跟踪器上解释的那样:

“Sorry, but this bug is not reproducible and does not crash VLC at all.” -Jean-Baptiste Kempf

“很抱歉,但是此错误不可复制,并且根本不会使VLC崩溃。” -让·巴蒂斯特·肯普夫(Jean-Baptiste Kempf)

“If you land on this ticket through a news article claiming a critical flaw in VLC, I suggest you to read the above comment first and reconsider your (fake) news sources.” -Francois Cartegnie

“如果您通过声称具有VLC严重缺陷的新闻来获得这张票,我建议您首先阅读以上评论,然后重新考虑您的(虚假)新闻来源。” -弗朗索瓦·卡特尼(Francois Cartegnie)

“This does not crash a normal release of VLC 3.0.7.1” -Jean-Baptiste Kempf

“这不会使VLC 3.0.7.1的正常发行版本崩溃”-Jean-Baptiste Kempf

Update: Here’s VideoLAN’s more lengthy response. According to the developers, there isn’t a flaw in the current VLC software at all.

更新 :这是VideoLAN的冗长响应。 根据开发人员的说法,当前的VLC软件根本没有缺陷。

So, a reporter, opened a bug on our bugtracker, which is outside of the reporting policy, aka, mail us in private on the security alias.Of course, our bugtracker is public.

因此,一名记者在我们的bugtracker上打开了一个bug,该bug不在报告策略之内,也就是以安全别名私下给我们发送邮件。当然,我们的bugtracker是公开的。

We could not, of course reproduce the issue, and tried to contact the security researcher, in private.

我们当然不能重现此问题,并试图私下与安全研究人员联系。

— VideoLAN (@videolan) July 24, 2019

— VideoLAN(@videolan) 2019年7月24日

翻译自: https://www.howtogeek.com/434487/no-you-dont-need-to-uninstall-vlc/

ubuntu 卸载vlc

你可能感兴趣的:(安全漏洞,安全,ubuntu,linux,信息安全)