Secunia
|
|

|
|
|
|
|
|
|
|
|
|
|
|
|
| onedeafeye | VLC media player plugin for Firefox |
|---|---|
|
16th Jul, 2011 09:45 |
|
Ranking: 2 Posts: 24 User Since: 11th Jun, 2009 System Score: N/A Location: N/A |
I just updated VLC to v1.1.11 and did a scan, and it still comes up as having an insecure Firefox plugin. I read the PSI links and they seem to refer to older versions of Firefox (I have FF 5.0.1), and I also don't have the plugin installed. Could someone please check to see if this information is current and still valid, and why it would show an insecure plugin where none exists? Thanks. |
| Anthony Wells | RE: VLC media player plugin for Firefox | ||||||||
|
16th Jul, 2011 13:13 | ||||||||
| Score: 2324 Posts: 3,203 User Since: 19th Dec 2007 System Score: N/A Location: N/A |
Hi , "Yes" it is valid and "No" it is not likely to be fixed in the foreseeable future . All the info you require is here :- http://secunia.com/community/forum/?forum=2&vendor... Take care Anthony -- It always seems impossible until its done. Nelson Mandela |
||||||||
|
|||||||||
| onedeafeye | RE: VLC media player plugin for Firefox | ||||||||
|
16th Jul, 2011 17:24 | ||||||||
| Score: 2 Posts: 24 User Since: 11th Jun 2009 System Score: N/A Location: N/A Last edited on 16th Jul, 2011 17:26 |
Thanks for your response. Everything I read suggested that updating to the next version would be the solution, and I read nothing about whether VLC 1.1.11 is vulnerable or not. So, sidestepping that issue, if I run VLC in a sandbox, will that be safe? As an afterthought edit, is there a media player with the abilities of VLC that you could recommend as being capable and safe? |
||||||||
|
|||||||||
| Anthony Wells | RE: VLC media player plugin for Firefox | ||||||||
|
16th Jul, 2011 17:54 | ||||||||
| Score: 2324 Posts: 3,203 User Since: 19th Dec 2007 System Score: N/A Location: N/A Last edited on 16th Jul, 2011 18:00 |
Hello again , You must have missed something ; this (other) thread applies to version 1.1.10 and nothing has changed for 1.1.11 :ie : the Ff plug-in is insecure and the PSI "secure browsing" module bug always reports it as being there and insecure" - it also links to alternatives :- http://secunia.com/community/forum/thread/show/979... A sandbox is never 100% secure but I do consider it to be a very important security tool :eg: I use Sandboxie with it's Drop (my) Rights setting enabled . If you do not know what your sandbox does , how it does it or how to set it , you may wish to seek advice at the publisher's Forum . Anthony -- It always seems impossible until its done. Nelson Mandela |
||||||||
|
|||||||||
| onedeafeye | RE: VLC media player plugin for Firefox | ||||||||
|
16th Jul, 2011 18:13 | ||||||||
| Score: 2 Posts: 24 User Since: 11th Jun 2009 System Score: N/A Location: N/A |
Thanks, I did miss the info you linked to. I think that answers my questions adequately. And I use Sandboxie as well, with my rights dropped. I think I'm done with this one. Thanks for the help. | ||||||||
|
|||||||||
Not a customer already?Learn more about how our market leading Vulnerability Management solutions can help you manage risk and ensure compliance. |