Arch Linux

Please read this before reporting a bug:
https://wiki.archlinux.org/title/Bug_reporting_guidelines

Do NOT report bugs when a package is just outdated, or it is in the AUR. Use the 'flag out of date' link on the package page, or the Mailing List.

REPEAT: Do NOT report bugs for outdated packages!
Tasklist

FS#10903 - Buffer overlow in VLC

Attached to Project: Arch Linux
Opened by name withheld (Gullible Jones) - Sunday, 13 July 2008, 19:27 GMT
Last edited by Greg (dolby) - Wednesday, 16 July 2008, 08:59 GMT
Task Type Bug Report
Category Packages: Extra
Status Closed
Assigned To Tobias Kieslich (tobias)
Architecture All
Severity Critical
Priority Normal
Reported Version 2007.08-2
Due in Version Undecided
Due Date Undecided
Percent Complete 100%
Votes 0
Private No

Details

Description:

The version of VLC in the repos contains a buffer overflow bug that could result in the execution of arbitrary code:

http://www.videolan.org/security/sa0806.html

The current version, 0.8.6i, fixes this.
This task depends upon

Closed by  Greg (dolby)
Wednesday, 16 July 2008, 08:59 GMT
Reason for closing:  Fixed
Comment by Eric Belanger (Snowman) - Wednesday, 16 July 2008, 00:59 GMT
FYI, I'll work on the update. It'll use the ffmpeg in testing.
Comment by Eric Belanger (Snowman) - Wednesday, 16 July 2008, 05:07 GMT
It's now in testing: vlc 0.8.6i-1
I've also updated the compiled-in static ffmpeg version (close  FS#10872 ).

Loading...