Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bugzilla DB migration completed. Please report issues to Infra team via email via infra@gentoo.org or IRC
Bug 450438 (CVE-2013-1868) - <media-video/vlc-2.0.5: Buffer overflows in freetype renderer and HTML subtitle parser (CVE-2013-1868)
Summary: <media-video/vlc-2.0.5: Buffer overflows in freetype renderer and HTML subtit...
Status: RESOLVED FIXED
Alias: CVE-2013-1868
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Gentoo Security
URL: http://www.videolan.org/security/sa13...
Whiteboard: B2 [glsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2013-01-05 18:20 UTC by kipplasterjoe
Modified: 2014-11-05 22:09 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description kipplasterjoe 2013-01-05 18:20:04 UTC
Current stable VLC is vulnerable, details see here: http://www.videolan.org/security/sa1301.html
Comment 1 Sean Amoss gentoo-dev Security 2013-01-06 16:21:48 UTC
(In reply to comment #0)
> Current stable VLC is vulnerable, details see here:
> http://www.videolan.org/security/sa1301.html

Thank you for the report.

video herd, may we stabilize =media-video/vlc-2.0.5 ?
Comment 2 Tomáš Chvátal (RETIRED) gentoo-dev 2013-01-12 16:14:10 UTC
I did amd64 x86 ppc and ppc64.

@Alpha:
please stabilise =media-video/vlc-2.0.5 and media-libs/opus-1.0.1
Comment 3 Agostino Sarubbo gentoo-dev 2013-02-08 16:39:32 UTC
alpha stable
Comment 4 Sean Amoss gentoo-dev Security 2013-03-17 12:53:54 UTC
Adding to existing GLSA draft after CVE has been assigned.
Comment 5 GLSAMaker/CVETool Bot gentoo-dev 2013-08-31 18:51:49 UTC
CVE-2013-1868 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-1868):
  Multiple buffer overflows in VideoLAN VLC media player 2.0.4 and earlier
  allow remote attackers to cause a denial of service (crash) and execute
  arbitrary code via vectors related to the (1) freetype renderer and (2) HTML
  subtitle parser.
Comment 6 GLSAMaker/CVETool Bot gentoo-dev 2014-11-05 22:09:58 UTC
This issue was resolved and addressed in
 GLSA 201411-01 at http://security.gentoo.org/glsa/glsa-201411-01.xml
by GLSA coordinator Sean Amoss (ackle).