vlc before 0.8.6c allows arbitrary code execution via a multitude of vectors
Bug #122207 reported by
William Grant
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
VLC media player |
Fix Released
|
Undecided
|
Unassigned | ||
vlc (Debian) |
Fix Released
|
Unknown
|
|||
vlc (Ubuntu) |
Fix Released
|
High
|
Unassigned | ||
Dapper |
Invalid
|
High
|
Unassigned | ||
Edgy |
Won't Fix
|
High
|
Unassigned | ||
Feisty |
Won't Fix
|
High
|
Unassigned | ||
Gutsy |
Fix Released
|
High
|
Unassigned |
Bug Description
Binary package hint: vlc
vlc in dapper, edgy, feisty and gutsy contains the flaws specified in CVE-2007-3316. The usual arbitrary code execution or DoS by a remote attacker. See http://
Changed in vlc: | |
importance: | Undecided → High |
status: | New → Confirmed |
importance: | Undecided → High |
status: | New → Confirmed |
importance: | Undecided → High |
status: | New → Confirmed |
importance: | Undecided → High |
status: | New → Confirmed |
Changed in vlc: | |
status: | New → Fix Released |
Changed in vlc: | |
status: | Unknown → Fix Released |
Changed in vlc: | |
status: | Confirmed → Won't Fix |
Changed in vlc (Ubuntu Dapper): | |
status: | New → Invalid |
To post a comment you must log in.
fixed in gutsy
vlc (0.8.6. release. c-0ubuntu1) gutsy; urgency=low
* SECURITY UPDATE: Format string injection in multiple plugins could 2007-0017. diff vlc-nox. install: Add libtelx_plugin.so (fixes FTBFS).
lead to arbitrary code execution and/or DoS.
* New upstream security and bugfix release, 0.8.6c (LP: #121511).
* References
CVE-2007-0256
CVE-2007-3316
* debian/patches/: Remove 020_flac.diff and 030_CVE-
(subsumed by new upstream release).
* debian/
-- Daniel T Chen <email address hidden> Mon, 25 Jun 2007 01:53:37 -0400