From ${URL} : Description Some vulnerabilities with an unknown impact have been reported in VLC Media Player. The vulnerabilities are caused due to unspecified errors. No further information is currently available. The vulnerabilities are reported in versions prior to 2.0.7. Solution: Update to version 2.0.7. Provided and/or discovered by: Reported by the vendor. Original Advisory: http://www.videolan.org/vlc/releases/2.0.7.html @maintainer(s): after the bump, in case we need to stabilize the package, please say explicitly if it is ready for the stabilization or not.
That's the vaguest vulnerability message I've seen to date.
I have no idea whether to GLSA this or not.
GLSA vote: no, since we can't categorize the vuln.
Oops, my bad, didn't notice that we skipped stable. Arches, please stabilize =media-video/vlc-2.0.7, target arches: alpha amd64 ppc ppc64 x86. Thanks!
(In reply to Chris Reffett from comment #1) > That's the vaguest vulnerability message I've seen to date. I agree, but now the upstream changelog says: Fix a memory leak when creating AVI files Fix two XSS vulnerabilities in the Web UI Fix memory exhaustion vulnerability in some playlist files I guess B3 is enough
amd64 stable
x86 stable
ppc stable
alpha stable
ppc64 stable
GLSA vote: no Counting previous no from Chris, closing this as noglsa