vlc 0.8.6.release.e+x264svn20071224+faad2.6.1-0ubuntu3.1 source package in Ubuntu
Changelog
vlc (0.8.6.release.e+x264svn20071224+faad2.6.1-0ubuntu3.1) hardy-security; urgency=low
* SECURITY UPDATE: multiple denials of service, arbitrary code execution and
arbitrary file overwriting vulnerabilities. (LP: #238873)
- debian/patches/032_CVE-2007-6683.diff: Assume unsafe Mozilla variable
settings. Fixes file overwriting. Patch from upstream git.
- debian/patches/033_CVE-2008-0073.diff: Check that the RTSP stream ID
isn't too large. Fixes arbitrary code execution. Patch from upstream git.
- debian/patches/034_CVE-2008-1686.diff: Check that the Speex header mode
is positive. Fixes arbitrary code execution. Patch from upstream git.
- debian/patches/038_CVE-2008-1768.diff: Fix a buffer overflow in the MP4
decoder, and an integer overflow in both the Cinepak and Real decoders.
Patches from upstream git.
- debian/patches/035_CVE-2008-1769.diff: Perform an appropriate boundary
check on frames in Cinepak streams. Fixes denial of service. Patch from
upstream git.
- debian/patches/036_CVE-2008-1881.diff: Fix subtitle format strings.
Properly fixes CVE-2007-6681, an arbitrary code execution vulnerability.
Patch from upstream git.
- debian/patches/037_CVE-2008-2147.diff: Only search for plugins in the
normal path. Fixes arbitrary code execution. Patch from upstream git.
- debian/patches/038_CVE-2008-2430.diff: Fix integer overflow in the WAV
demuxer. Fixes arbitrary code execution. Path from upstream git.
- References:
+ CVE-2007-6681
+ CVE-2007-6683
+ CVE-2008-0073
+ CVE-2008-1686
+ CVE-2008-1768
+ CVE-2008-1769
+ CVE-2008-1881
+ CVE-2008-2147
+ CVE-2008-2430
-- William Grant <email address hidden> Sun, 13 Jul 2008 10:45:55 +1000
Upload details
- Uploaded by:
- William Grant on 2008-08-07
- Uploaded to:
- Hardy
- Original maintainer:
- MOTU
- Architectures:
- any
- Section:
- graphics
- Urgency:
- Low Urgency
See full publishing history Publishing
| Series | Published | Component | Section |
|---|
Downloads
| File | Size | SHA-256 Checksum |
|---|---|---|
| vlc_0.8.6.release.e+x264svn20071224+faad2.6.1.orig.tar.gz | 17.5 MiB | 564af976b69cc1a46f6a9d80f50144a8e62c55cd893d411b40b449e18f5fdb2e |
| vlc_0.8.6.release.e+x264svn20071224+faad2.6.1-0ubuntu3.1.diff.gz | 46.0 KiB | 501ad23c2b5e66d4c15211fbf570a570d5224df4c0a795819e132cc7ccd378b4 |
| vlc_0.8.6.release.e+x264svn20071224+faad2.6.1-0ubuntu3.1.dsc | 2.3 KiB | e2bea00a39b363f51f64a4918b7a0e465c5adfb6ee93954bfc3b38e485a4b37d |
Available diffs
Binary packages built by this source
- libvlc0: No summary available for libvlc0 in ubuntu hardy.
No description available for libvlc0 in ubuntu hardy.
- libvlc0-dev: No summary available for libvlc0-dev in ubuntu hardy.
No description available for libvlc0-dev in ubuntu hardy.
- mozilla-plugin-vlc: No summary available for mozilla-plugin-vlc in ubuntu hardy.
No description available for mozilla-plugin-vlc in ubuntu hardy.
- vlc: No summary available for vlc in ubuntu hardy.
No description available for vlc in ubuntu hardy.
- vlc-nox: No summary available for vlc-nox in ubuntu hardy.
No description available for vlc-nox in ubuntu hardy.
- vlc-plugin-alsa: No summary available for vlc-plugin-alsa in ubuntu hardy.
No description available for vlc-plugin-alsa in ubuntu hardy.
- vlc-plugin-arts: No summary available for vlc-plugin-arts in ubuntu hardy.
No description available for vlc-plugin-arts in ubuntu hardy.
- vlc-plugin-esd: No summary available for vlc-plugin-esd in ubuntu hardy.
No description available for vlc-plugin-esd in ubuntu hardy.
- vlc-plugin-ggi: No summary available for vlc-plugin-ggi in ubuntu hardy.
No description available for vlc-plugin-ggi in ubuntu hardy.
- vlc-plugin-glide: No summary available for vlc-plugin-glide in ubuntu hardy.
No description available for vlc-plugin-glide in ubuntu hardy.
- vlc-plugin-pulse: No summary available for vlc-plugin-pulse in ubuntu hardy.
No description available for vlc-plugin-pulse in ubuntu hardy.
- vlc-plugin-sdl: No summary available for vlc-plugin-sdl in ubuntu hardy.
No description available for vlc-plugin-sdl in ubuntu hardy.
- vlc-plugin-svgalib: No summary available for vlc-plugin-svgalib in ubuntu hardy.
No description available for vlc-plugin-svgalib in ubuntu hardy.
- wxvlc: No summary available for wxvlc in ubuntu hardy.
No description available for wxvlc in ubuntu hardy.

