You Do not Must Uninstall VLC from Your Pc [Updated]


Image for article titled You Don't Need to Uninstall VLC from Your Computer [Updated]

Information broke in the present day that the VLC Media Participant—immensely standard and Lifehacker-recommended—allegedly has a fairly extreme bug that might enable enable a “booby-trapped” video, as The Register put it, to both crash the participant or execute distant code. The previous? An annoyance. The latter? An enormous safety problem, one which’d we advocate uninstalling VLC to handle till its creator, VideoLAN, comes out with a patch.

However we’re not recommending that motion simply but, as a result of there’s a bit extra to the story. The bug report for the problem has been open for 4 weeks, however VideoLAN president and lead VLC developer Jean-Baptiste Kempf left a collection of feedback in the present day indicating that the alleged bug isn’t as huge a deal as everyone seems to be making it out to be. In three separate feedback, he wrote:

“This doesn’t crash a standard launch of VLC 3.0.7.1″

“For those who land on this ticket by way of a information article claiming a essential flaw in VLC, I counsel you to learn the above remark first and rethink your (faux) information sources.”

“Sorry, however this bug shouldn’t be reproducible and doesn’t crash VLC in any respect.”

VideoLAN additionally took to Twitter to speak concerning the bug—or moderately, the non-bug.

What must you do with VLC?

[Updated 7/24] We’ve revealed VideoLAN’s official response on the finish of this text, which fits into nice element about how this probably VLC-breaking bug is definitely nothing. I’ve left the unique textual content from our article as-is, as a result of I feel it’s necessary to indicate our thought course of behind why we really useful taking a extra measured response than uninstalling VLC and throwing your laptop computer into a hearthor no matter else everybody was suggesting. 

First, you’ll be able to obtain a proof-of-concept video from the unique filer of the bug to see if it crashes your VLC upon playback. (The Register reviews it crashed their model of VLC—model 3.0.7—however I had no issues with the file on my Home windows-based model of VLC 3.0.7.1.) That’s not necessairly going to inform you whether or not your model of VLC is secure from distant code execution, however it’s an fascinating information level price wanting into.

Second, in the event you’re utilizing VLC on a Mac, you’re completely effective. The bug in query allegedly solely impacts Home windows, Unix, and Linux variations of VLC. As effectively, the bug solely seems to have an effect on .MKV recordsdata—in the event you don’t even know what that’s, or don’t watch them, you’re effective.

Third, and most significantly, it’s important to determine who to consider: the safety advisory from Germany’s Pc Emergency Response Workforce (CERT-Bund), which introduced this complete mess to mild, or VideoLAN itself, which is denying the problem’s existence and severity.

I feel the waters are muddy sufficient that I wouldn’t go uninstalling VLC from all my techniques simply but. What you may do, nevertheless, is put it in outing. In the interim, swap to a secondary media participant—or, dare I say it, again to Home windows Media Participant—and set that up as your default participant for media recordsdata (Begin Button > kind in “Default apps” > swap your music and video participant to one thing else).

Image for article titled You Don't Need to Uninstall VLC from Your Computer [Updated]

Screenshot: David Murphy

Take note of VLC’s ChangeLog, and look forward to the corporate to launch a brand new model of the participant that patches up the bug—if it’s even planning to take action. If just a few minor variations (or one main model) go by and all appears effectively, contemplate going again to utilizing VLC.

It doesn’t matter what, ensure you’re at all times downloading the newest updates for VLC (by way of Assist > Examine for Updates). It’s additionally nice to have VLC’s “Activate updates notifier” choice enabled in its settings, so that you’ll know instantly when it’s time for a brand new model of the app.

Image for article titled You Don't Need to Uninstall VLC from Your Computer [Updated]

Screenshot: David Murphy

Up to date 7/24/19 at 10:00 am: VideoLAN has revealed a full rationalization for the alleged horrific bug. All the things’s effective!



Supply hyperlink