Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug
Bug#: 211575
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Robert Buchholz <rbu@gentoo.org>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 211575 depends on: Show dependency tree
Bug 211575 blocks:

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2008-02-26 22:47 0000
CVE-2008-0984 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-0984):
  The MP4 demuxer (mp4.c) for VLC media player 0.8.6d and earlier allows remote
  attackers to overwrite arbitrary memory and execute arbitrary code via a
  malformed MP4 file.

------- Comment #1 From Robert Buchholz 2008-02-26 22:52:46 0000 -------
Patch is here:
http://www.videolan.org/patches/vlc-0.8.6-CORE-2008-0130.patch

And this should be fixed in the "e" release, whenever that goes public. So I'd
go for patching our 0.8.6d-r1. Media-video, what do you think?

------- Comment #2 From Alexis Ballier 2008-02-26 23:04:55 0000 -------
http://download.videolan.org/pub/videolan/vlc/0.8.6e/vlc-0.8.6e.tar.bz2 exists

it's been tagged a few days ago, but I didn't see an announcement yet.
lemme check what's up with this

------- Comment #3 From Christian Faulhammer 2008-02-28 11:28:53 0000 -------
0.8.6e is officially released.

------- Comment #4 From Alexis Ballier 2008-02-28 12:02:45 0000 -------
(In reply to comment #3)
> 0.8.6e is officially released.
> 

yeah but the build hadn't finished when I had to leave home ;)

I'll bump it most likely this evening

------- Comment #5 From Alexis Ballier 2008-02-28 18:10:41 0000 -------
(In reply to comment #4)
> (In reply to comment #3)
> > 0.8.6e is officially released.
> > 
> 
> yeah but the build hadn't finished when I had to leave home ;)
> 
> I'll bump it most likely this evening
> 

its bumped now

------- Comment #6 From Christian Faulhammer 2008-02-29 07:49:01 0000 -------
Please arches do:

media-video/vlc-0.8.6e 
target keywords are "alpha amd64 ppc ~ppc64 sparc x86 ~x86-fbsd"

------- Comment #7 From Christian Faulhammer 2008-02-29 08:59:28 0000 -------
x86 stable

------- Comment #8 From Ferris McCormick 2008-02-29 15:12:52 0000 -------
Initial test on sparc results in a BadAlloc error from X followed by a
SegFault.  I'll investigate further on another system, but for now, I'm holding
off on sparc.

------- Comment #9 From Ferris McCormick 2008-02-29 16:18:42 0000 -------
(In reply to comment #8)
> Initial test on sparc results in a BadAlloc error from X followed by a
> SegFault.  I'll investigate further on another system, but for now, I'm holding
> off on sparc.
> 

This problem is specific to one out-of-date system.  On my reference system
(whick is completely current) it does not occur.  Hence,

Stable for sparc.

------- Comment #10 From Raúl Porcel 2008-03-02 14:45:37 0000 -------
alpha stable, thanks Tobias

------- Comment #11 From Tobias Scherbaum 2008-03-04 19:34:21 0000 -------
ppc stable

------- Comment #12 From Santiago M. Mola 2008-03-07 12:47:53 0000 -------
amd64 stable, sorry for the delay.

------- Comment #13 From Peter Volkov 2008-03-07 16:13:08 0000 -------
Fixed in release snapshot.

------- Comment #14 From Pierre-Yves Rofes 2008-03-07 22:49:41 0000 -------
GLSA 200803-13

Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug