Summary: | <media-video/vlc-3.0.11: Buffer overflow in hxxx_AnnexB_to_xVC via crafted H264 Annex B file (CVE-2020-13428) | ||
---|---|---|---|
Product: | Gentoo Security | Reporter: | Sam James <sam> |
Component: | Vulnerabilities | Assignee: | Gentoo Security <security> |
Status: | RESOLVED INVALID | ||
Severity: | normal | CC: | media-video |
Priority: | Normal | Keywords: | CC-ARCHES, PullRequest |
Version: | unspecified | Flags: | nattka:
sanity-check+
|
Hardware: | All | ||
OS: | Linux | ||
URL: | https://www.videolan.org/security/sb-vlc3011.html | ||
See Also: | https://github.com/gentoo/gentoo/pull/16185 | ||
Whiteboard: | B3 [noglsa cve] | ||
Package list: |
=media-video/vlc-3.0.11
|
Runtime testing required: | --- |
Description
Sam James
![]() ![]() ![]() ![]() @maintainer(s), please bump to 3.0.11. @maintainer(s), please advise if ready for stabilisation, or call yourself Unable to check for sanity:
> package masked: media-video/vlc-3.0.11, by keywords: -sparc
All sanity-check issues have been resolved arm64 stable This doesn't affect us: https://www.videolan.org/security/sb-vlc3011.html "The affected code was only used by macOS/iOS hardware accelerated decoder (VideoToolbox), meaning other platforms are unaffected." |