New Update VLC Media Player - Updates Thread

silversurfer

Super Moderator
Thread author
Verified
Top Poster
Staff Member
Malware Hunter
Forum Veteran
Aug 17, 2014
12,731
123,854
8,399
Homepage: VLC: Official site - Free multimedia solutions for all OS! - VideoLAN


Changes between 3.0.19 and 3.0.20:
----------------------------------

Video Output:
- Fix green line in fullscreen in D3D11 video output
- Fix crash with some AMD drivers old versions
- Fix events propagation issue when double-clicking with mouse wheel

Decoders:
- Fix crash when AV1 hardware decoder fails

Interface:
- Fix annoying disappearance of the Windows fullscreen controller

Demuxers:
- Fix potential security issue (OOB Write) on MMS:// by checking user size bounds
Source: https://code.videolan.org/videolan/vlc/-/raw/3.0.x/NEWS

Note: This new version is not available yet to download on official homepage, but rather is available on download servers: Index of /pub/videolan/vlc/3.0.20/
 
VLC Media Player is great. With the recent news of the exploits (dll sideloading) is VLC Media Player still 'safe' to use? I download it from VideoLAN's website and don't have the plugins enabled in my web browsers or automatic updates. As a general statement should it be considered secure if it's 0/67 in VirusTotal and the sha265 hash matches? And is this (Hybrid Analysis) overkill?

Thank you!
 

VLC Media Player 3.0.21​

Changes between 3.0.20 and 3.0.21:
----------------------------------

Decoders:
* Improve Opus ambisonic support
* Fix some ASS subtitle rendering issues
* Fix Opus in MP4 behaviour
* Fix VAAPI hw decoding with some drivers

Input:
* Add support for HTTP content range handling according to RFC 9110
* Fix some HLS Adaptive Streaming not working in audio-only mode

Video Output:
* Super Resolution scaling with AMD GPUs
* The D3D11 HDR option can also turn on/off HDR for all sources regardless of
the display
* Improve subtitles rendering on Apple platforms of notably Asian languages
by correcting font fallback lookups

Video Filter:
* New AMD VQ Enhancer filter
* Add D3D11 option to use NVIDIA TrueHDR to generate HDR from SDR sources

Audio Output:
* Fix regression on macOS causing crashes when using audio devices
with more than 9 channels

Services Discovery:
* Fix exposed UPnP directory URL schemes to be compliant with RFC 3986

Contrib:
* Update FFmpeg to 4.4.4
* Update dav1d to 1.4.2
* Update libvpx to 1.14.1

libVLC:
* the HWND passed to libvlc_media_player_set_hwnd must have the WS_CLIPCHILDREN
style set.
* Fix crashes when using caopengllayer

Misc:
* Fix various warnings, leaks and potential crashes
* Fix security integer overflow in MMS module
Source: https://code.videolan.org/videolan/vlc/-/raw/3.0.x/NEWS

Note: The new version is not available yet to download on official homepage, rather downloading from here: Index of /pub/videolan/vlc/3.0.21/
 
VLC Media Player 3.0.22 RC1
Changes between 3.0.21 and 3.0.22-rc1:
----------------------------------

Core:
* Assume subpictures are in SDR by default

Windows:
* Add Windows ARM64 builds (Minimum Windows 10 RS5 17763 / 1809)
* Fix support for Windows XP SP3
* Allow renaming/moving/deleting of playing file on Windows
* Restrict SystemParametersInfo calls to Windows XP

Decoders:
* Fix Opus channel mapping
* Fix hardware decoding with VideoToolbox of XVID MPEG-4 video
* Add dav1d-all-layers option
* Fix DVD CEA-608 captions parsing
* Fix ProRes 4:4:4:4
* Disable decoding using libdca, libmpeg2 and liba52 by default in favor of libavcodec

Demuxers:
* Handle mkv-use-chapter-codec option
* Add A_ATRAC/AT1 support in matroska
* Prevent FLAC seeking logic get stuck
* Handle pictures in FLAC
* Fix VOB/AOB LPCM/MLP detection failing occasionally
* Cut QNap title on first invalid character
* Fix display of certain JPEG files
* Fix playback of very short ASF files (duration less than 1s)
* Fix crashes in multiple demuxers (reported by rub.de, oss-fuzz and others)

Input:
* Fix SFTP seeking for large files on 32-bit OS

Interface:
* Add option to use dark palette (Qt)
* Add compilation support for Qt6 and newer versions of Qt5

Service Discovery:
* UPnP: remove SAT>IP channel list fallback

Video Output:
* Use a better stretch mode in wingdi
* Fetch missing device information when running in UWP

Video Filter:
* Add AMD GPU Frame Rate Doubler (Direct3D11)

Download: Index of /vlc/release-win64/
 
VLC Media Player 3.0.22 (as stable release) is available for downloading manually from here: Index of /vlc/release-win64/

Changes between 3.0.21 and 3.0.22:
----------------------------------

Core:
* Assume subpictures are in SDR by default

Windows:
* Add Windows ARM64 builds (Minimum Windows 10 RS5 17763 / 1809)
* Fix support for Windows XP SP3
* Allow renaming/moving/deleting of playing file on Windows
* Restrict SystemParametersInfo calls to Windows XP

Decoders:
* Fix Opus channel mapping
* Fix hardware decoding with VideoToolbox of XVID MPEG-4 video
* Add dav1d-all-layers option
* Fix DVD CEA-608 captions parsing
* Fix ProRes 4:4:4:4
* Disable decoding using libdca, libmpeg2 and liba52 by default in favor of libavcodec

Demuxers:
* Add support for DMX audio music (MUS) files
* Handle mkv-use-chapter-codec option
* Add A_ATRAC/AT1 support in matroska
* Prevent FLAC seeking logic get stuck
* Handle pictures in FLAC
* Fix VOB/AOB LPCM/MLP detection failing occasionally
* Cut QNap title on first invalid character
* Fix display of certain JPEG files
* Fix playback of very short ASF files (duration less than 1s)
* Multiple fixes in MPEG-TS
* Fix crashes in multiple demuxers (reported by rub.de, oss-fuzz and others)

Input:
* Fix SFTP seeking for large files on 32-bit OS

Interface:
* Qt: Add option to use dark palette
* Qt: Add compilation support for newer versions of Qt5
* Qt: Fix scrolling on volume slider
* macOS: fix crashes when drag'n drop items in the playlist
* KDE: fix MPRIS state when started from file

Service Discovery:
* UPnP: remove SAT>IP channel list fallback

Video Output:
* Use a better stretch mode in wingdi
* Fetch missing device information when running in UWP

Video Filter:
* Add AMD GPU Frame Rate Doubler (Direct3D11)
* Improve visualization of low frequencies in spectrogram

Contrib:
* Update amf to 1.4.34
* Update dav1d to 1.5.1
* Update FFmpeg to 4.4.5
* Update freetype to 2.13.1
* Update gettext to 0.22.5
* Update gcrypt to 1.10.1
* Update glew to 2.1.0
* Update gmp to 6.3.0
* Udpate gnutls to 3.8.10
* Update harfbuzz to 11.5.0
* Update iconv to 1.17
* Update libarchive to 3.8.0 including support for RAR 5.0
* Update libass to 0.17.3
* Update libbluray to 1.4.0
* Update libmatroska to 1.7.0
* Update libogg to 1.3.6
* Update libpng to 1.6.50
* Update libvpx to 1.15.2
* Update lua to 5.1.5
* Update openjpeg to 2.5.0
* Update orc to 0.4.33
* Update srt to 1.5.3
* Update taglib to 1.13.1
* Update zlib to 1.3.1
* and more 3rd party updates
* libmpeg2, libdca and liba52 are no longer build by default
* build ragel inside harfbuzz if necessary

Misc:
* gnutls: remove manual DH prime bits setting
* Avoid very large fonts in portrait mode
* Update of most translations

Many thanks to the Sovereign Tech Agency (Home | Sovereign Tech Agency), and
especially their Sovereign Tech Fund program, for helping VLC sustainability and safety.
Thanks to oss-fuzz as well for their help and resources to find issues.
Thanks to their support, 3.0.22 becomes the VLC release with the most security fixes ever!

Security:
* Heap Buffer Overflow READ in TY, NSV, CVDsub, SPU, Subrip, TX3G, MPJEG demuxers and decoders
* Heap Buffer Overflow Write in RLE, MP4, TX3G demuxers and decoders
* Assert failure in AVI, MP4 demuxers and Core
* Null dereferences in CSS, Flac and VTT modules
* Use-after Free in SVG decoder
* Crash in Subtitles core, in jpeg2 inside TS
* Multiple crashes and OOB in CEA-708 subtitles
* OOB read on Oggspot, MP4
* Multiple leaks in MKV, ASF/WMV, CAF and PS demuxers, Ogg, Theora, Vorbis,
WebVTT and SVCD decoders
* Busy loop in WebVTT
(The list above is not exhaustive)
 
  • Like
Reactions: silversurfer
Do you know the reason why VLC version 3.0.22 still isnt available to download on the VLC main site?
I don't know, No official info, AFAIK
But well-known websites like MajorGeeks and Softpedia has already the version 3.0.22

One important point, according to change log... new version 3.0.22 includes also fixes in terms of Security:
 
From a Dutch site:
We asked VLC why the release of VLC 3.0.22 is taking so long and received a response today. Felix Paul Kühne, one of the developers of VLC, states that critical regressions have been found in version 3.0.22, causing the launch to be postponed. Instead, VLC media player 3.0.23 will be released. Hopefully before the end of this year, according to Kühne.
 
VLC Media Player 3.0.23 (stable release) is available for downloading manually from here: Index of /videolan/vlc/3.0.23/
NOTE: Version 3.0.23 should be soon ready also on the official homepage...

Changes between 3.0.22 and 3.0.23:
----------------------------------

Codecs:
* Fix WebVTT line positioning
* Expose additional audio codec information (notably for Flac 24bit)

Demuxers:
* fix some JPEG files wih JFIF headers

Windows:
* config_GetUserDir() no longer tries to create the folder on Windows (#29488)
* Fix images display with D3D11
* Improve dark palette in Qt interface
* Fix compilation of OpenGL modules

Security:
* Fix null deref in libass, undefined shift in theora and cc-708, integer overflow in daala,
Infinite loop in h264 parsing, buffer overflow in png and multiple format-overflows

Misc:
* Prepare compatibility for taglib 2.0, Qt6, FFmpeg8, mingw-w64 v13 and newer versions of
libplacebo and pupnp
 

You may also like...