Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 182389 - media-video/vlc-0.8.6{b,-r1} Format string injection in Vorbis, Theora, SAPand CDDA plugins (CVE 2007-3316)
Summary: media-video/vlc-0.8.6{b,-r1} Format string injection in Vorbis, Theora, SAPan...
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High normal (vote)
Assignee: Gentoo Security
URL: http://www.videolan.org/sa0702.html
Whiteboard: B2? [glsa] jaervosz
Keywords:
Depends on:
Blocks:
 
Reported: 2007-06-17 20:46 UTC by Alexis Ballier
Modified: 2011-10-30 22:37 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Alexis Ballier gentoo-dev 2007-06-17 20:46:52 UTC
A security problem has been found in vlc, any version <0.8.6c (that has just been released to fix that) is vulnerable, see url for details

Official changelog is : 

Changes between 0.8.6b and 0.8.6c:
----------------------------------

Various bugfixes, notably:
 * Windows Vista compatibility
 * Cropping in Direct3D
 * Fullscreen change crash on Mac OS X
 * RSS filter string overflow
 * Few memory leaks
 * MKV demuxer crash (related to seeking)

CDDA / Vorbis / Theora / SAP plugins:
 * Security updates (VideoLAN-SA-0702)

Demuxers:
 * Fixed a problem with detecting embedded subtitles (GAB2 format) in AVI

Decoders:
 * Updated FLAC API compatibility

Input:
 * Support for new v4l2 encoder API

Localisation:
 * New localisation: Arabic, Persian



I tend to consider this grave and worth a premature stabilisation.
From my (maintainer) point of view, a premature stabilisation should be sane as there are only bugfixes differences between 0.8.6b (that is already stable on most arches, bug #179862) and 0.8.6c (no feature added)


I'm not sure what's your (security team) way of handling such things, so I'll let you add arches if you think it's appropriate
Comment 1 Alexis Ballier gentoo-dev 2007-06-22 07:34:25 UTC
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3316

Adding arches as security is not answering and I really don't like having such a bug in stable. vlc 0.8.6c is almost the same as 0.8.6b withtout the security issues, please test and mark it stable
Comment 2 Alexis Ballier gentoo-dev 2007-06-22 07:35:53 UTC
Adding arches (for real this time, hopefuly) as security is not answering and I really don't like having such
a bug in stable. vlc 0.8.6c is almost the same as 0.8.6b withtout the security
issues, please test and mark it stable
Comment 3 Christoph Mende (RETIRED) gentoo-dev 2007-06-22 12:01:05 UTC
amd64 done
Comment 4 Gustavo Zacarias (RETIRED) gentoo-dev 2007-06-22 20:20:13 UTC
sparc stable.
Comment 5 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2007-06-23 18:10:57 UTC
@Alexis, sorry for the late answer. My dev box died and I had to replace it. Thx for my work :)
Comment 6 Raúl Porcel (RETIRED) gentoo-dev 2007-06-24 17:56:57 UTC
alpha/x86 stable
Comment 7 Tobias Scherbaum (RETIRED) gentoo-dev 2007-06-24 19:38:19 UTC
ppc stable
Comment 8 Pierre-Yves Rofes (RETIRED) gentoo-dev 2007-07-28 21:29:15 UTC
GLSA 200707-12, thanks everybody!