Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 159845 - media-video/vlc <= 0.8.6 format string vulnerability (CVE-2007-0017)
Summary: media-video/vlc <= 0.8.6 format string vulnerability (CVE-2007-0017)
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High normal (vote)
Assignee: Gentoo Security
URL: http://projects.info-pull.com/moab/MO...
Whiteboard: A2 [glsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2007-01-03 05:38 UTC by Matt Drew (RETIRED)
Modified: 2007-02-11 10:24 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Matt Drew (RETIRED) gentoo-dev 2007-01-03 05:38:03 UTC
http://secunia.com/advisories/23592/

vlc has a format string vulnerability in the handling of udp:// URLs or M3U files containing udp:// URLs.  Exploits are already available for OS X (ppc and x86) from the vulnerability announcement URL.  Impact is code execution with the privileges of the user running vlc.
Comment 1 Matt Drew (RETIRED) gentoo-dev 2007-01-03 05:40:13 UTC
setting status and CC'ing herd.
Comment 2 Diego Elio Pettenò (RETIRED) gentoo-dev 2007-01-03 11:48:38 UTC
Sigh, I would have told it a couple of hours ago but bugzy died. vlc-0.8.6-r1 patched is in tree now.
Comment 3 Tavis Ormandy (RETIRED) gentoo-dev 2007-01-04 04:24:29 UTC
arches please test and mark stable media-video/vlc-0.8.6-r1

target keywords: KEYWORDS="alpha amd64 sparc x86"
Comment 4 Tobias Scherbaum (RETIRED) gentoo-dev 2007-01-04 12:22:26 UTC
We have nothing to do here ...
Comment 5 Christian Faulhammer (RETIRED) gentoo-dev 2007-01-04 12:49:52 UTC
x86 done
Comment 6 Bryan Østergaard (RETIRED) gentoo-dev 2007-01-06 13:39:35 UTC
Alpha stable.
Comment 7 Markus Rothe (RETIRED) gentoo-dev 2007-01-07 11:45:05 UTC
vlc not stable on ppc64 yet.
Comment 8 Malcolm Lashley (RETIRED) gentoo-dev 2007-01-10 20:06:58 UTC
amd64 done
Comment 9 Matt Drew (RETIRED) gentoo-dev 2007-01-12 18:37:42 UTC
CVE-2007-0017
Comment 10 Gustavo Zacarias (RETIRED) gentoo-dev 2007-01-15 21:17:00 UTC
sparc stable.
sorry for the delay on this one, but it was b0rked until i've rebuilt it with the just recently stabled wxGTK (rebuilding wxGTK & vlc over and over again didn't help it).
Comment 11 Raphael Marichez (Falco) (RETIRED) gentoo-dev 2007-01-15 23:30:24 UTC
(In reply to comment #10)
> sparc stable.
> sorry for the delay on this one, but it was b0rked until i've rebuilt it with
> the just recently stabled wxGTK (rebuilding wxGTK & vlc over and over again
> didn't help it).
> 

np, thanks Gustavo
Comment 12 Matthias Geerdsen (RETIRED) gentoo-dev 2007-01-26 14:47:19 UTC
GLSA 200701-24

missing moderation mail for -announce, closing when it hit the list
Comment 13 Matthias Geerdsen (RETIRED) gentoo-dev 2007-01-27 19:28:32 UTC
finally closing