Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 473938 - <media-video/vlc-2.0.7 : Multiple Vulnerabilities
Summary: <media-video/vlc-2.0.7 : Multiple Vulnerabilities
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor (vote)
Assignee: Gentoo Security
URL: https://secunia.com/advisories/53656/
Whiteboard: B3 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2013-06-20 16:12 UTC by Agostino Sarubbo
Modified: 2013-09-05 10:51 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Agostino Sarubbo gentoo-dev 2013-06-20 16:12:15 UTC
From ${URL} :

Description

Some vulnerabilities with an unknown impact have been reported in VLC 
Media Player.

The vulnerabilities are caused due to unspecified errors. No further 
information is currently available.

The vulnerabilities are reported in versions prior to 2.0.7.


Solution:
Update to version 2.0.7.

Provided and/or discovered by:
Reported by the vendor.

Original Advisory:
http://www.videolan.org/vlc/releases/2.0.7.html


@maintainer(s): after the bump, in case we need to stabilize the package, please say explicitly if it is ready for the stabilization or not.
Comment 1 Chris Reffett (RETIRED) gentoo-dev Security 2013-06-30 13:07:48 UTC
That's the vaguest vulnerability message I've seen to date.
Comment 2 Chris Reffett (RETIRED) gentoo-dev Security 2013-08-23 15:00:54 UTC
I have no idea whether to GLSA this or not.
Comment 3 Chris Reffett (RETIRED) gentoo-dev Security 2013-08-29 18:12:16 UTC
GLSA vote: no, since we can't categorize the vuln.
Comment 4 Chris Reffett (RETIRED) gentoo-dev Security 2013-08-29 18:15:49 UTC
Oops, my bad, didn't notice that we skipped stable. Arches, please stabilize =media-video/vlc-2.0.7, target arches: alpha amd64 ppc ppc64 x86. Thanks!
Comment 5 Agostino Sarubbo gentoo-dev 2013-08-29 19:16:30 UTC
(In reply to Chris Reffett from comment #1)
> That's the vaguest vulnerability message I've seen to date.

I agree, but now the upstream changelog says:

Fix a memory leak when creating AVI files
Fix two XSS vulnerabilities in the Web UI
Fix memory exhaustion vulnerability in some playlist files

I guess B3 is enough
Comment 6 Agostino Sarubbo gentoo-dev 2013-08-30 18:42:15 UTC
amd64 stable
Comment 7 Agostino Sarubbo gentoo-dev 2013-09-01 15:33:12 UTC
x86 stable
Comment 8 Agostino Sarubbo gentoo-dev 2013-09-01 15:52:47 UTC
ppc stable
Comment 9 Agostino Sarubbo gentoo-dev 2013-09-01 16:05:11 UTC
alpha stable
Comment 10 Agostino Sarubbo gentoo-dev 2013-09-05 10:46:01 UTC
ppc64 stable
Comment 11 Sergey Popov gentoo-dev 2013-09-05 10:51:04 UTC
GLSA vote: no

Counting previous no from Chris, closing this as noglsa