ALT-BU-2015-2339-1
Branch sisyphus update bulletin.
Closed vulnerabilities
BDU:2016-01038
Уязвимость операционной системы Ubuntu и медиаплеера VideoLAN Media Player, позволяющая нарушителю вызвать отказ в обслуживании
BDU:2019-03980
Уязвимость демультиплексора MP4 программы-медиапроигрывателя VideoLAN VLC, позволяющая нарушителю выполнить произвольный код или вызвать отказ в обслуживании
BDU:2019-03981
Уязвимость демультиплексора MP4 программы-медиапроигрывателя VideoLAN VLC, позволяющая нарушителю выполнить произвольный код или вызвать отказ в обслуживании
BDU:2019-03982
Уязвимость демультиплексора MP4 программы-медиапроигрывателя VideoLAN VLC, позволяющая нарушителю выполнить произвольный код или вызвать отказ в обслуживании
BDU:2019-03984
Уязвимость реализации протокола RTP программы-медиапроигрывателя VideoLAN VLC, позволяющая нарушителю выполнить произвольный код или вызвать отказ в обслуживании
Modified: 2024-11-21
CVE-2014-9597
The picture_pool_Delete function in misc/picture_pool.c in VideoLAN VLC media player 2.1.5 allows remote attackers to execute arbitrary code or cause a denial of service (DEP violation and application crash) via a crafted FLV file.
- 20150116 VLC Media Player 2.1.5 Memory Corruption Vulnerabilities (CVE-2014-9597, CVE-2014-9597)
- 20150116 VLC Media Player 2.1.5 Memory Corruption Vulnerabilities (CVE-2014-9597, CVE-2014-9597)
- http://www.binarysniper.net/2015/01/vlc-media-player-215-memory-corruption.html
- http://www.binarysniper.net/2015/01/vlc-media-player-215-memory-corruption.html
- GLSA-201603-08
- GLSA-201603-08
- https://trac.videolan.org/vlc/attachment/ticket/13389/windbglog.txt
- https://trac.videolan.org/vlc/attachment/ticket/13389/windbglog.txt
- https://trac.videolan.org/vlc/ticket/13389
- https://trac.videolan.org/vlc/ticket/13389
Modified: 2024-11-21
CVE-2014-9598
The picture_Release function in misc/picture.c in VideoLAN VLC media player 2.1.5 allows remote attackers to execute arbitrary code or cause a denial of service (write access violation) via a crafted M2V file.
- 20150116 VLC Media Player 2.1.5 Memory Corruption Vulnerabilities (CVE-2014-9597, CVE-2014-9597)
- 20150116 VLC Media Player 2.1.5 Memory Corruption Vulnerabilities (CVE-2014-9597, CVE-2014-9597)
- http://www.binarysniper.net/2015/01/vlc-media-player-215-memory-corruption.html
- http://www.binarysniper.net/2015/01/vlc-media-player-215-memory-corruption.html
- GLSA-201603-08
- GLSA-201603-08
- https://trac.videolan.org/vlc/attachment/ticket/13390/windbglog.txt
- https://trac.videolan.org/vlc/attachment/ticket/13390/windbglog.txt
- https://trac.videolan.org/vlc/ticket/13390
- https://trac.videolan.org/vlc/ticket/13390
Modified: 2024-11-21
CVE-2014-9625
The GetUpdateFile function in misc/update.c in the Updater in VideoLAN VLC media player before 2.1.6 performs an incorrect cast operation from a 64-bit integer to a 32-bit integer, which allows remote attackers to conduct buffer overflow attacks and execute arbitrary code via a crafted update status file, aka an "integer truncation" vulnerability.
- http://openwall.com/lists/oss-security/2015/01/20/5
- http://openwall.com/lists/oss-security/2015/01/20/5
- https://github.com/videolan/vlc/commit/fbe2837bc80f155c001781041a54c58b5524fc14
- https://github.com/videolan/vlc/commit/fbe2837bc80f155c001781041a54c58b5524fc14
- https://www.videolan.org/security/sa1501.html
- https://www.videolan.org/security/sa1501.html
Modified: 2024-11-21
CVE-2014-9626
Integer underflow in the MP4_ReadBox_String function in modules/demux/mp4/libmp4.c in VideoLAN VLC media player before 2.1.6 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a box size less than 7.
- http://openwall.com/lists/oss-security/2015/01/20/5
- http://openwall.com/lists/oss-security/2015/01/20/5
- https://github.com/videolan/vlc/commit/2e7c7091a61aa5d07e7997b393d821e91f593c39
- https://github.com/videolan/vlc/commit/2e7c7091a61aa5d07e7997b393d821e91f593c39
- https://www.videolan.org/security/sa1501.html
- https://www.videolan.org/security/sa1501.html
Modified: 2024-11-21
CVE-2014-9627
The MP4_ReadBox_String function in modules/demux/mp4/libmp4.c in VideoLAN VLC media player before 2.1.6 performs an incorrect cast operation from a 64-bit integer to a 32-bit integer, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via a large box size.
- http://openwall.com/lists/oss-security/2015/01/20/5
- http://openwall.com/lists/oss-security/2015/01/20/5
- https://github.com/videolan/vlc/commit/2e7c7091a61aa5d07e7997b393d821e91f593c39
- https://github.com/videolan/vlc/commit/2e7c7091a61aa5d07e7997b393d821e91f593c39
- https://www.videolan.org/security/sa1501.html
- https://www.videolan.org/security/sa1501.html
Modified: 2024-11-21
CVE-2014-9628
The MP4_ReadBox_String function in modules/demux/mp4/libmp4.c in VideoLAN VLC media player before 2.1.6 allows remote attackers to trigger an unintended zero-size malloc and conduct buffer overflow attacks, and consequently execute arbitrary code, via a box size of 7.
- http://openwall.com/lists/oss-security/2015/01/20/5
- http://openwall.com/lists/oss-security/2015/01/20/5
- https://github.com/videolan/vlc/commit/2e7c7091a61aa5d07e7997b393d821e91f593c39
- https://github.com/videolan/vlc/commit/2e7c7091a61aa5d07e7997b393d821e91f593c39
- https://www.videolan.org/security/sa1501.html
- https://www.videolan.org/security/sa1501.html
Modified: 2024-11-21
CVE-2014-9630
The rtp_packetize_xiph_config function in modules/stream_out/rtpfmt.c in VideoLAN VLC media player before 2.1.6 uses a stack-allocation approach with a size determined by arbitrary input data, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted length value.
- http://openwall.com/lists/oss-security/2015/01/20/5
- http://openwall.com/lists/oss-security/2015/01/20/5
- https://github.com/videolan/vlc/commit/204291467724867b79735c0ee3aeb0dbc2200f97
- https://github.com/videolan/vlc/commit/204291467724867b79735c0ee3aeb0dbc2200f97
- https://www.videolan.org/security/sa1501.html
- https://www.videolan.org/security/sa1501.html
Modified: 2024-11-21
CVE-2014-9743
Cross-site scripting (XSS) vulnerability in the httpd_HtmlError function in network/httpd.c in the web interface in VideoLAN VLC Media Player before 2.2.0 allows remote attackers to inject arbitrary web script or HTML via the path info.
- http://git.videolan.org/?p=vlc.git%3Ba=commit%3Bh=fe5063ec5ad1873039ea719eb1f137c8f3bda84b
- http://git.videolan.org/?p=vlc.git%3Ba=commit%3Bh=fe5063ec5ad1873039ea719eb1f137c8f3bda84b
- 20140318 [Quantum Leap Advisory] #QLA140216 - VLC Reflected XSS vulnerability
- 20140318 [Quantum Leap Advisory] #QLA140216 - VLC Reflected XSS vulnerability
- http://www.quantumleap.it/vlc-reflected-xss-vulnerability/
- http://www.quantumleap.it/vlc-reflected-xss-vulnerability/
- 66307
- 66307
Modified: 2024-11-21
CVE-2016-3941
Buffer overflow in the AStreamPeekStream function in input/stream.c in VideoLAN VLC media player before 2.2.0 allows remote attackers to cause a denial of service (crash) via a crafted wav file, related to "seek across EOF."
- openSUSE-SU-2016:1651
- openSUSE-SU-2016:1651
- 1035456
- 1035456
- https://bugs.launchpad.net/ubuntu/+source/vlc/+bug/1533633
- https://bugs.launchpad.net/ubuntu/+source/vlc/+bug/1533633
- [vlc-commits] 20150131 stream: handle seek across EOF correctly (hopefully)
- [vlc-commits] 20150131 stream: handle seek across EOF correctly (hopefully)