FreeBSD Bugzilla – Attachment 91852 Details for
Bug 129356
Document CVE-2008-5276 for multimedia/vlc-devel
Home
|
New
|
Browse
|
Search
|
[?]
|
Reports
|
Help
|
New Account
|
Log In
Remember
[x]
|
Forgot Password
Login:
[x]
file.txt
file.txt (text/plain), 1.37 KB, created by
Joseph S. Atkinson
on 2008-12-02 01:40:00 UTC
(
hide
)
Description:
file.txt
Filename:
MIME Type:
Creator:
Joseph S. Atkinson
Created:
2008-12-02 01:40:00 UTC
Size:
1.37 KB
patch
obsolete
><vuln vid="1972d685-c010-11dd-a69e-000d8825e644"> > <topic>Real Media integer overflow might trigger heap-based buffer overflow in vlc-devel</topic> > <affects> > <package> > <name>vlc-devel</name> > <range><gt>0.9.*,2</gt><lt>0.9.8,3</lt></range> > </package> > </affects> > <description> > <body xmlns="http://www.w3.org/1999/xhtml"> > <p>Tobias Klein (tk@trapkit.de) identified:</p> > <blockquote cite="http://www.trapkit.de/advisories/TKADV2008-013.txt"> > <p>The VLC media player contains an integer overflow vulnerability while parsing malformed RealMedia (.rm) files. The vulnerability leads to a heap overflow that can be exploited by a (remote) attacker to execute arbitrary code in the context of VLC media player.</p> > </blockquote> > <p>The VideoLAN Security Advisory 0811 entry states:</p> > <blockquote cite="http://www.videolan.org/security/sa0811.html"> > <p>When parsing the header of an invalid Real Media file an integer overflow might occur then trigger a heap-based buffer overflows.</p> > </blockquote> > </body> > </description> > <references> > <freebsdpr>ports/129355</freebsdpr> > <cvename>CVE-2008-5276</cvename> > <url>http://www.trapkit.de/advisories/TKADV2008-013.txt</url> > <url>http://www.videolan.org/security/sa0811.html</url> > </references> > <dates> > <discovery>2008-11-14</discovery> > <entry>2008-12-01</entry> > </dates> > </vuln>
You cannot view the attachment while viewing its details because your browser does not support IFRAMEs.
View the attachment on a separate page
.
View Attachment As Raw
Actions:
View
Attachments on
bug 129356
: 91852