The cumulative security patch is available today and addresses thepotential for exploits surrounding buffer overflows (read/write) andsandbox integrity within the player, which might allow malicious usersto gain access to a user's computer.
The file(1) command contains a buffer overflow vulnerability that canbe leveraged by an attacker to execute arbitrary code under theprivileges of another user.
Remote attackers may exploit the buffer overflow condition to run arbitrary code on a Snort sensor with the privileges of the Snort IDS process, which typically runs as the superuser.