Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 450438 (CVE-2013-1868)

Summary: <media-video/vlc-2.0.5: Buffer overflows in freetype renderer and HTML subtitle parser (CVE-2013-1868)
Product: Gentoo Security Reporter: kipplasterjoe
Component: VulnerabilitiesAssignee: Gentoo Security <security>
Status: RESOLVED FIXED    
Severity: normal CC: media-video
Priority: Normal    
Version: unspecified   
Hardware: All   
OS: Linux   
URL: http://www.videolan.org/security/sa1301.html
Whiteboard: B2 [glsa]
Package list:
Runtime testing required: ---

Description kipplasterjoe 2013-01-05 18:20:04 UTC
Current stable VLC is vulnerable, details see here: http://www.videolan.org/security/sa1301.html
Comment 1 Sean Amoss (RETIRED) gentoo-dev Security 2013-01-06 16:21:48 UTC
(In reply to comment #0)
> Current stable VLC is vulnerable, details see here:
> http://www.videolan.org/security/sa1301.html

Thank you for the report.

video herd, may we stabilize =media-video/vlc-2.0.5 ?
Comment 2 Tomáš Chvátal (RETIRED) gentoo-dev 2013-01-12 16:14:10 UTC
I did amd64 x86 ppc and ppc64.

@Alpha:
please stabilise =media-video/vlc-2.0.5 and media-libs/opus-1.0.1
Comment 3 Agostino Sarubbo gentoo-dev 2013-02-08 16:39:32 UTC
alpha stable
Comment 4 Sean Amoss (RETIRED) gentoo-dev Security 2013-03-17 12:53:54 UTC
Adding to existing GLSA draft after CVE has been assigned.
Comment 5 GLSAMaker/CVETool Bot gentoo-dev 2013-08-31 18:51:49 UTC
CVE-2013-1868 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-1868):
  Multiple buffer overflows in VideoLAN VLC media player 2.0.4 and earlier
  allow remote attackers to cause a denial of service (crash) and execute
  arbitrary code via vectors related to the (1) freetype renderer and (2) HTML
  subtitle parser.
Comment 6 GLSAMaker/CVETool Bot gentoo-dev 2014-11-05 22:09:58 UTC
This issue was resolved and addressed in
 GLSA 201411-01 at http://security.gentoo.org/glsa/glsa-201411-01.xml
by GLSA coordinator Sean Amoss (ackle).