New 0.9.5 release, security fixes
Bug #289263 reported by
John Dong
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
vlc (Ubuntu) |
Fix Released
|
Undecided
|
Unassigned |
Bug Description
Binary package hint: vlc
Just a heads-up seems like upstream released 0.9.5 now, which includes a security fix for TiVo stream parsing and miscellaneous bugfixes. I don't know how we want to handle this at this point in the release cycle.
Related branches
lp://staging/~motumedia/vlc/ubuntu
- VCS imports: Pending requested
CVE References
Changed in vlc: | |
status: | New → Confirmed |
To post a comment you must log in.
We will handle this in -updates / -security.
Just as a FYI regarding the Tivo demux overflow: blackbook: /tmp]$ vlc exploit.mpg (10-28 12:35) i486-linux- gnu' '--enable- maintaner- mode' '--enable-release' '--prefix=/usr' '--enable-libtool' '--enable- fast-install' '--with- binary- version= 1ubuntu3' '--disable- update- check' '--disable-gnome' '--disable-gtk' '--disable- familiar' '--disable-fb' '--enable-ggi' '--enable-sdl' '--enable-esd' '--enable-mad' '--enable-arts' '--enable-jack' '--enable-pulse' '--enable-lirc' '--enable-a52' '--enable-aa' '--enable-dvbpsi' '--enable-mozilla' '--with- mozilla- pkg=libxul- plugin' '--disable-kde' '--enable-mp4' '--enable-dvb' '--disable- satellite' '--enable-ogg' '--enable-vorbis' '--enable-shout' '--enable-qt4' '--disable-slp' '--enable-flac' '--disable-skins' '--disable- basic-skins' '--enable-skins2' '--enable-freetype' '--enable-mkv' '--enable-speex' '--enable-caca' '--enable-live555' '--enable-libmpeg2' '--enable-fribidi' '--enable-cdio' '--enable-mod' '--enable-theora' '--enable-modplug' '--enable-dvdnav' '--enable-gnutls' '--enable-ffmpeg' '--enable-ncurses' '--enable-smb' '--disable- gnomevfs' '--enable-bonjour' '--enable-mpc' '--enable-vcd' '--enable-vcdx' '--enable-notify' '--enable-twolame' '--enable-x264' '--enable-faad' '--disable-zvbi' '--enable-telx' '--enable- mediacontrol- bindings' '--disable-atmo' '--enable-taglib' '--enable-libass' '--enable-libdca' '--enable-alsa' '--enable-dv' '--enable-v4l' '--enable-v4l2' '--enable-pvr' '--enable-svgalib' '--enable-dvd' '--without-dvdcss' 'build_ alias=i486- linux-gnu' 'CFLAGS=-g -O2' 'LDFLAGS= -Wl,--as- needed' 'CPPFLAGS=' 'CXXFLAGS=-g -O2' i686/cmov/ libc.so. 6(__fortify_ fail+0x48) [0xb7df4558] i686/cmov/ libc.so. 6(__fortify_ fail+0x0) [0xb7df4510] vlc/demux/ libty_plugin. so[0xb43e9bc4] vlc/demux/ libty_plugin. so[0xb43e56a6]
[jdong@
VLC media player 0.9.4 Grishenko
[00000001] main libvlc debug: VLC media player - version 0.9.4 Grishenko - (c) 1996-2008 the VideoLAN team
[00000001] main libvlc debug: libvlc was configured with ./configure '--build=
[00000001] main libvlc debug: translation test: code is "C"
[00000001] main libvlc: Running vlc with the default interface. Use 'cvlc' to use vlc without interface.
[00000379] ty demux error: Unsupported SEQ bitmap size in master chunk
*** stack smashing detected ***: vlc terminated
======= Backtrace: =========
/lib/tls/
/lib/tls/
/usr/lib/
/usr/lib/
======= Memory map: ========
[...]
-fstack-protector nabs the attack, this is a DoS, not a arbitrary execution vulnerability, for Ubuntu.