This is not true. The exploit was fixed over a year ago (since v. 3.0.3): <a href="https://twitter.com/videolan/status/1153963312981389312?s=21" rel="nofollow">https://twitter.com/videolan/status/1153963312981389312?s=21</a>