vlc in Hardy needs a security update
Bug #238873 reported by
Bryan Fullerton
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
vlc (Ubuntu) |
Fix Released
|
High
|
William Grant | ||
Dapper |
Invalid
|
Undecided
|
Unassigned | ||
Feisty |
Won't Fix
|
Undecided
|
Unassigned | ||
Gutsy |
Won't Fix
|
Undecided
|
Unassigned | ||
Hardy |
Fix Released
|
High
|
William Grant | ||
Intrepid |
Fix Released
|
High
|
William Grant |
Bug Description
Binary package hint: vlc
Please upgrade vlc and related packages to 0.8.6h (or whatever is current when you get to this) as there are numerous security issues fixed since 0.8.6e that ships with Hardy.
http://
http://
http://
http://
Thanks,
Bryan
Changed in vlc: | |
importance: | Undecided → Medium |
status: | New → Confirmed |
Changed in vlc: | |
assignee: | nobody → wgrant |
status: | Triaged → In Progress |
Changed in vlc: | |
assignee: | nobody → wgrant |
status: | Triaged → In Progress |
To post a comment you must log in.
Changes between 0.8.6f and 0.8.6g
Security updates
* Removed VLC variable settings from Mozilla and ActiveX (CVE-2007-6683, VideoLAN-SA-0804)
* Removed loading plugins from the current directory (CVE-2008-2147, VideoLAN-SA-0805)
* Updated libpng on Windows and Mac OS X (CVE-2008-1382)
* Fixed libid3tag denial of service (CVE-2008-2109)
* Fixed libvorbis vulnerabilities (CVE-2008-1419, CVE-2008-1420, CVE-2008-1423)
* Fixed speex insufficient boundary check (CVE-2008-1686, oCERT-2008-004)