Re: CVE-2013-1868

2013-03-20 Thread Benjamin Drung
Am Mittwoch, den 20.03.2013, 23:03 +0200 schrieb Henri Salo: > On Wed, Mar 20, 2013 at 09:54:30PM +0100, Benjamin Drung wrote: > > Is there test case / file that triggers this bug? > > I don't have any. You can request such from upstream if you want or I can do > it. It would be nice if you coul

Re: CVE-2013-1868

2013-03-20 Thread Henri Salo
On Wed, Mar 20, 2013 at 09:54:30PM +0100, Benjamin Drung wrote: > Is there test case / file that triggers this bug? I don't have any. You can request such from upstream if you want or I can do it. --- Henri Salo signature.asc Description: Digital signature __

Re: CVE-2013-1868

2013-03-20 Thread Benjamin Drung
Am Mittwoch, den 20.03.2013, 13:56 +0200 schrieb Henri Salo: > > VLC 2.0.3-5 from testing is (probably) affected and VLC 2.0.5-1 from > > unstable is not affected. > > Could you submit this information to security tracker after you have verified > it? It's fixed in VLC 2.0.5 according to upstream

Re: CVE-2013-1868

2013-03-20 Thread Henri Salo
> VLC 2.0.3-5 from testing is (probably) affected and VLC 2.0.5-1 from > unstable is not affected. Could you submit this information to security tracker after you have verified it? > > > > http://git.videolan.org/?p=vlc/vlc-2.0.git;a=commitdiff;h=9b0414dc7f5c18ff2951175cf076779c444efd70 > >

Re: CVE-2013-1868

2013-03-20 Thread Benjamin Drung
Am Mittwoch, den 20.03.2013, 11:23 +0200 schrieb Henri Salo: > Hello, > > Could you check if Debian packages of VLC are affected of CVE-2013-1868, > thank you. VLC 2.0.3-5 from testing is (probably) affected and VLC 2.0.5-1 from unstable is not affected. > References: >

CVE-2013-1868

2013-03-20 Thread Henri Salo
Hello, Could you check if Debian packages of VLC are affected of CVE-2013-1868, thank you. References: https://security-tracker.debian.org/tracker/CVE-2013-1868 http://www.openwall.com/lists/oss-security/2013/03/17/1 http://git.videolan.org/?p=vlc/vlc-2.0.git;a=commitdiff;h