[Secure-testing-team] Bug#480370: mozilla-plugin-vlc: CVE-2007-6683 is not fixed at all

Remi Denis-Courmont rdenis at simphalempin.com
Fri May 9 15:32:47 UTC 2008


Package: mozilla-plugin-vlc
Version: 0.8.6.e-2.1
Severity: grave
Tags: security patch
Justification: user security hole


The "vlc" binary package part of CVE-2007-6683 has been fixed as per
#458318. However, the issue affecting the mozilla plugin as noted here:
http://mailman.videolan.org/pipermail/vlc-devel/2007-December/037726.html
seems to still be wide open.

Upstream patch is here, but note that this will partially disable existing
functionality:
http://git.videolan.org/?p=vlc.git;a=commit;h=b426b192c7712eaa08c5f55d08ef648226d6d421

As far as I know affects both Etch and Lenny.

Regards,

-- System Information:
Debian Release: lenny/sid
  APT prefers unstable
  APT policy: (100, 'unstable'), (100, 'testing')
Architecture: i386 (i686)

Kernel: Linux 2.6.25 (SMP w/2 CPU cores)
Locale: LANG=fr_FR.UTF-8, LC_CTYPE=fr_FR.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash

Versions of packages mozilla-plugin-vlc depends on:
ii  libc6                       2.7-10       GNU C Library: Shared libraries
ii  libgcc1                     1:4.3.0-4    GCC support library
ii  libice6                     2:1.0.4-1    X11 Inter-Client Exchange library
ii  libsm6                      2:1.0.3-1+b1 X11 Session Management library
ii  libstdc++6                  4.3.0-4      The GNU Standard C++ Library v3
ii  libvlc0                     0.8.6.e-2.1  multimedia player and streamer lib
ii  libx11-6                    2:1.0.3-7    X11 client-side library
ii  libxt6                      1:1.0.5-3    X11 toolkit intrinsics library
ii  vlc                         0.8.6.e-2.1  multimedia player and streamer
ii  vlc-nox                     0.8.6.e-2.1  multimedia player and streamer (wi

mozilla-plugin-vlc recommends no packages.

-- no debconf information





More information about the Secure-testing-team mailing list