Jump to content
EduGeek EdSec 2026 is Go! 27th Oct in Derby! Join us for a day of EdTech security focused talks, networking, and an evening social ×

In January, The EU Starts Running Bug Bounties On Free And Open Source Software


Recommended Posts

Posted

Link: In January, the EU starts running Bug Bounties on Free and Open Source Software

 

...In January the European Commission is launching 14 out of a total of 15 bug bounties on Free Software projects that the EU institutions rely on. A bug bounty is a prize for people who actively search for security issues. The amount of the bounty depends on the severity of the issue uncovered and the relative importance of the software. The software projects chosen were previously identified as candidates in the inventories and a public survey.

 

You can contribute to the projects below by analysing the software, and by submitting any bugs or vulnerabilities you find to the involved bug bounty platforms...

 

The list of Software projects and the bug bounties:

 

Bug Bounties.JPG

  • 5 months later...
Posted

VLC 3.0.7 release and EU-FOSSA

 

We just released VLC 3.0.7, a minor update of VLC branch 3.0.x. This release is a bit special, because it has more security issues fixed than any other version of VLC.

 

This high number of security issues is due to the sponsoring of a bug bounty program funded by the European Commission, during the FOSSA program.

 

Severity

According to our scale, we have had 33 valid security issues fixed thanks to this program:

 

  • 2 high security issues, (only one was present in 3.0.x)
  • 21 medium security issues
  • 20 low security issues

The 2 more important issues are an Out-of-Bound Write and a Stack Buffer Overflow.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...