[CVE-2008-1489] buffer overflow in MP4 demuxer in vlc 0.8.6e
Bug #207284 reported by
William Grant
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
vlc (Gentoo Linux) |
Fix Released
|
Medium
|
|||
vlc (Ubuntu) |
Fix Released
|
Undecided
|
Unassigned | ||
Dapper |
Fix Released
|
Medium
|
Emanuele Gentili | ||
Edgy |
Won't Fix
|
Medium
|
Emanuele Gentili | ||
Feisty |
Fix Released
|
Medium
|
Emanuele Gentili | ||
Gutsy |
Fix Released
|
Medium
|
Emanuele Gentili | ||
Hardy |
Fix Released
|
Undecided
|
Unassigned |
Bug Description
Binary package hint: vlc
DESCRIPTION:
A vulnerability has been reported in VLC Media Player, which
potentially can be exploited by malicious people to compromise a
user's system.
The vulnerability is caused due to an integer overflow error within
"MP4_ReadBox_
exploited to cause a heap-based buffer overflow via e.g. a MP4 file
with a specially crafted RDRF atom.
Successful exploitation may allow execution of arbitrary code.
The vulnerability is reported in version 0.8.6e. Other versions may
also be affected.
SOLUTION:
Fixed in the GIT repository.
http://
Changed in vlc: | |
status: | New → Confirmed |
status: | New → Confirmed |
status: | New → Confirmed |
status: | New → Confirmed |
Changed in vlc: | |
status: | Unknown → In Progress |
Changed in vlc: | |
status: | In Progress → Fix Released |
Changed in vlc: | |
status: | In Progress → Fix Committed |
status: | Won't Fix → Fix Committed |
status: | In Progress → Fix Committed |
status: | In Progress → Fix Committed |
Changed in vlc: | |
status: | Fix Committed → Won't Fix |
Changed in vlc: | |
status: | Fix Committed → Fix Released |
Changed in vlc (Gentoo Linux): | |
importance: | Unknown → Medium |
To post a comment you must log in.
This bug was fixed in the package vlc - 0.8.6.release. e+x264svn200712 24+faad2. 6.1-0ubuntu2
--------------- release. e+x264svn200712 24+faad2. 6.1-0ubuntu2) hardy; urgency=low
vlc (0.8.6.
* Add 031_CVE_ 2008_1489. diff from git head
to fix CVE-2008-1489. (LP: #207284)
-- Mario Limonciello <email address hidden> Thu, 27 Mar 2008 21:55:17 -0500