Bug 146099 - [security] update multimedia/vlc to 1.0.6, document internally discovered exploit
Summary: [security] update multimedia/vlc to 1.0.6, document internally discovered exp...
Status: Closed FIXED
Alias: None
Product: Ports & Packages
Classification: Unclassified
Component: Individual Port(s) (show other bugs)
Version: Latest
Hardware: Any Any
: Normal Affects Only Me
Assignee: Sylvio Cesar Teixeira
URL:
Keywords:
Depends on:
Blocks:
 
Reported: 2010-04-27 23:10 UTC by Joseph S. Atkinson
Modified: 2010-05-02 02:00 UTC (History)
0 users

See Also:


Attachments
file.shar (2.78 KB, text/plain)
2010-04-27 23:10 UTC, Joseph S. Atkinson
no flags Details

Note You need to log in before you can comment on or make changes to this bug.
Description Joseph S. Atkinson 2010-04-27 23:10:02 UTC
VideoLAN has released 1.0.6 to address several vulnerabilities they discovered while working towards the 1.1.0 release. These vulnerabilities could potentially allow for a specially crafted file to execute code.

Fix: This shar file contains two patches. The first is the update patch for vlc, the second is the vuln.xml entry, sans this PR number.

Patch attached with submission follows:
Comment 1 Sylvio Cesar Teixeira freebsd_committer freebsd_triage 2010-04-28 01:46:46 UTC
Responsible Changed
From-To: freebsd-ports-bugs->sylvio

I'll take it.
Comment 2 dfilter service freebsd_committer freebsd_triage 2010-05-02 01:49:03 UTC
sylvio      2010-05-02 00:48:49 UTC

  FreeBSD ports repository

  Modified files:
    multimedia/vlc       Makefile distinfo 
  Log:
  - Update to 1.0.6
  
  PR:             ports/146099
  Submitted by:   Joseph S. Atkinson <jsa@wickedmachine.net> (maintainer)
  
  Revision  Changes    Path
  1.220     +1 -2      ports/multimedia/vlc/Makefile
  1.36      +3 -3      ports/multimedia/vlc/distinfo
_______________________________________________
cvs-all@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/cvs-all
To unsubscribe, send any mail to "cvs-all-unsubscribe@freebsd.org"
Comment 3 dfilter service freebsd_committer freebsd_triage 2010-05-02 01:52:59 UTC
sylvio      2010-05-02 00:52:40 UTC

  FreeBSD ports repository

  Modified files:
    security/vuxml       vuln.xml 
  Log:
  - VideoLAN has released 1.0.6 to address serveral vulnerabilities they discoverd while working towards the 1.1.0 release. These vulnerabilities could potentially allow for a specially crafted file to execute code.
  
  PR:             ports/146099
  Submitted by:   Joseph S. Atkinson <jsa@wickedmachine.net> (maintainer)
  
  Revision  Changes    Path
  1.2151    +28 -1     ports/security/vuxml/vuln.xml
_______________________________________________
cvs-all@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/cvs-all
To unsubscribe, send any mail to "cvs-all-unsubscribe@freebsd.org"
Comment 4 Sylvio Cesar Teixeira freebsd_committer freebsd_triage 2010-05-02 01:54:45 UTC
State Changed
From-To: open->closed

Committed. Thanks!