Comment 2 for bug 1350356

Revision history for this message
Owain Kenway (o-kenway) wrote : Re: vlc 2.1.5 is released, software upgrade is needed

Hi,

The vulnerability CVE 2014-3466 in GNUTLS has *not* been fixed in Trusty (at time of writing the current stable release). It's been fixed in libgnutls26, but not in libgnutls28 (which is what VLC actually uses) - see:

https://bugs.launchpad.net/ubuntu/+source/gnutls28/+bug/1326779

Cheers,
Dr Owain Kenway