Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Message-ID: <CA+e4TbdMu4LHbj8GU=xNdkF=97b2RZW0kmvsfDmnkZnKD7dEPA@mail.gmail.com>
Date: Mon, 30 Sep 2013 23:31:20 +0200
From: Laurent Butti <laurentb@...il.com>
To: oss-security@...ts.openwall.com
Subject: CVE request: VLC

Hi,

I have found a security issue in vlc 2.0.8 which was reported to VLC
team and fixed in both 2.0.9 and 2.1.0 (as "Fix buffer overflow in the
mp4a packetizer").

Here are the commit log and changelog:

* http://git.videolan.org/?p=vlc.git;a=commitdiff;h=9794ec1cd268c04c8bca13a5fae15df6594dff3e
* http://www.videolan.org/developers/vlc-branch/NEWS

Could a CVE be assigned?

Thanks,
Laurent Butti.

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.