|
Message-ID: <CA+e4TbdMu4LHbj8GU=xNdkF=97b2RZW0kmvsfDmnkZnKD7dEPA@mail.gmail.com> Date: Mon, 30 Sep 2013 23:31:20 +0200 From: Laurent Butti <laurentb@...il.com> To: oss-security@...ts.openwall.com Subject: CVE request: VLC Hi, I have found a security issue in vlc 2.0.8 which was reported to VLC team and fixed in both 2.0.9 and 2.1.0 (as "Fix buffer overflow in the mp4a packetizer"). Here are the commit log and changelog: * http://git.videolan.org/?p=vlc.git;a=commitdiff;h=9794ec1cd268c04c8bca13a5fae15df6594dff3e * http://www.videolan.org/developers/vlc-branch/NEWS Could a CVE be assigned? Thanks, Laurent Butti.
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.