Bug 1666 - New version of VLC (1.1.11) fixes some security issues + heap corruption / integer overflow in XSPF playlist parser
Summary: New version of VLC (1.1.11) fixes some security issues + heap corruption / in...
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 1
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact:
URL: http://www.videolan.org/developers/vl...
Whiteboard:
Keywords:
Depends on:
Blocks: 2267
  Show dependency treegraph
 
Reported: 2011-06-07 15:12 CEST by Sander Lepik
Modified: 2014-05-08 18:04 CEST (History)
6 users (show)

See Also:
Source RPM: vlc-1.1.9-3.mga1.src.rpm, vlc-1.1.9-4.mga1.tainted.src.rpm
CVE:
Status comment:


Attachments
List of 36 packages in vlc update (579 bytes, text/plain)
2011-07-18 22:24 CEST, Dave Hodgins
Details

Description Sander Lepik 2011-06-07 15:12:25 CEST
Description of problem:
Security issues are listed under Win / Mac OS X, so i'm not sure about them but heap corruption may cause problems too.
Comment 1 Ahmad Samir 2011-06-07 17:48:09 CEST
(Such reports are usually useless, packagers catch updates notifications from http://check.mageia.org/).
Comment 2 Olav Dahlum 2011-06-07 23:17:37 CEST
(In reply to comment #0)
> Description of problem:
> Security issues are listed under Win / Mac OS X, so i'm not sure about them but
> heap corruption may cause problems too.

Nevertheless, thanks for the reminder.

CC: (none) => odahlum

Comment 3 Ahmad Samir 2011-06-07 23:18:59 CEST
Actually, as Sander pointed out on IRC, the report isn't just about a version bump, it's about a version fixing some sec issues.
Comment 4 Ahmad Samir 2011-06-07 23:29:49 CEST
(Although it doesn't look that severe, i.e. doesn't have to be an official update.. just backports).
Comment 5 Nicolas Vigier 2011-06-30 23:28:29 CEST
CVE-2011-2194 :
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2194

CC: (none) => boklm

Comment 6 Frédéric "LpSolit" Buclin 2011-07-18 11:38:51 CEST
Two security bugs have also been fixed in VLC 1.1.11:

  Security:
   * Fix buffer overflows in the RealMedia demuxer (CVE-2011-2587)
     and the AVI one (CVE-2011-2588).

I see that VLC 1.1.11 has been uploaded to Cauldron. It should also be offered as a security update to Mageia 1.

CC: (none) => LpSolit, fundawang
Summary: New version of VLC (1.1.10) fixes some security issues + heap corruption / integer overflow in XSPF playlist parser => New version of VLC (1.1.11) fixes some security issues + heap corruption / integer overflow in XSPF playlist parser

Comment 7 Funda Wang 2011-07-18 13:37:49 CEST
I've uploaded vlc-1.1.11-0.1.mga1 into core/updates_testing and tainted/updates_testing.

Advisory text:
Several vulnerabilities were discovered and corrected in vlc:

VLC media player suffers from an integer overflow vulnerability in the XSPF playlist file parser. (CVE-2011-2194)
VLC media player suffers from a heap overflow vulnerability in the Real Media file parser and AVI file parser. (CVE-2011-2587, CVE-2011-2588).

The updated packages have been upgraded to the 1.1.11 version which is not vulnerable to these issues.

Assignee: bugsquad => qa-bugs

Comment 8 Dave Hodgins 2011-07-18 22:24:21 CEST
Created attachment 659 [details]
List of 36 packages in vlc update

There are 36 packages in core updates testing involved in this update
as well as 36 in tainted updates testing.  See attachment for list.
The two srpm packages are
vlc-1.1.11-0.1.mga1.src.rpm
vlc-1.1.11-0.1.mga1.tainted.src.rpm

I installed the 36 packages from Core Updates testing, confirmed
I could play audio and video files, and play a test video
http://goa103.free.fr/t_63455/media_player.php
in firefox, to test the mozilla plugin.

I then used urpmi --auto-select to update the packages with the
versions from tainted updates testing, and repeated the tests.

Testing complete on i586.
Comment 9 José Jorge 2011-07-19 11:19:36 CEST
Tested on x86_64 : OK also watching streaming TV.

CC: (none) => lists.jjorge

Comment 10 Michael Scherer 2011-07-20 00:01:33 CEST
That's interesting, so we have to do 2 updates advisory ?

CC: (none) => misc

Comment 11 Michael Scherer 2011-07-20 00:08:01 CEST
Ok, I did only one for now, was easier.
Comment 12 Michael Scherer 2011-07-20 00:08:49 CEST
Fixed

Status: NEW => RESOLVED
Resolution: (none) => FIXED

Comment 13 Frédéric "LpSolit" Buclin 2011-07-24 17:17:13 CEST
There is a severe regression with VLC 1.1.11: the audio and video are no longer in sync when playing a FLV or MP4 video. This problem disappears when reinstalling vlc-1.1.9-4.mga1.tainted. Is one of the Mageia patches responsible for this regression, or is this problem also visible upstream?
Comment 14 Frédéric "LpSolit" Buclin 2011-07-24 18:16:47 CEST
I reported this bug upstream: https://trac.videolan.org/vlc/ticket/5124
Comment 15 Samuel Verschelde 2011-07-24 21:09:13 CEST
This bug report being already closed, please open a new bug report depending on this one.

CC: (none) => stormi

Frédéric "LpSolit" Buclin 2011-07-25 00:12:38 CEST

Blocks: (none) => 2267

Nicolas Vigier 2014-05-08 18:04:57 CEST

CC: boklm => (none)


Note You need to log in before you can comment on or make changes to this bug.