aboutsummaryrefslogtreecommitdiffstats
path: root/security/vuxml
diff options
context:
space:
mode:
authormiwi <miwi@FreeBSD.org>2008-11-09 05:30:14 +0800
committermiwi <miwi@FreeBSD.org>2008-11-09 05:30:14 +0800
commita328a09847439639b4bffaa4abaf6fb9decd6719 (patch)
treed69c4b12e78bb8a5473e9a3524a7ea234393789e /security/vuxml
parentff31d4185f1d7e29894734f9164952ee84c01520 (diff)
downloadfreebsd-ports-graphics-a328a09847439639b4bffaa4abaf6fb9decd6719.tar.gz
freebsd-ports-graphics-a328a09847439639b4bffaa4abaf6fb9decd6719.tar.zst
freebsd-ports-graphics-a328a09847439639b4bffaa4abaf6fb9decd6719.zip
- Document vlc -- cue processing stack overflow
Diffstat (limited to 'security/vuxml')
-rw-r--r--security/vuxml/vuln.xml33
1 files changed, 33 insertions, 0 deletions
diff --git a/security/vuxml/vuln.xml b/security/vuxml/vuln.xml
index b095102b7ed..ff8bf1b548b 100644
--- a/security/vuxml/vuln.xml
+++ b/security/vuxml/vuln.xml
@@ -34,6 +34,39 @@ Note: Please add new entries to the beginning of this file.
-->
<vuxml xmlns="http://www.vuxml.org/apps/vuxml-1">
+ <vuln vid="4b09378e-addb-11dd-a578-0030843d3802">
+ <topic>vlc -- cue processing stack overflow</topic>
+ <affects>
+ <package>
+ <name>vlc</name>
+ <range><lt>0.8.6i_2,2</lt></range>
+ </package>
+ <package>
+ <name>vlc-devel</name>
+ <range><lt>0.9.6,3</lt></range>
+ </package>
+ </affects>
+ <description>
+ <body xmlns="http://www.w3.org/1999/xhtml">
+ <p>The VLC Team reports:</p>
+ <blockquote cite="http://www.videolan.org/security/sa0810.html">
+ <p>The VLC media player contains a stack overflow vulnerability while
+ parsing malformed cue files. The vulnerability may be exploited by a (remote)
+ attacker to execute arbitrary code in the context of VLC media player.
+ </p>
+ </blockquote>
+ </body>
+ </description>
+ <references>
+ <url>http://www.videolan.org/security/sa0810.html</url>
+ <url>http://www.trapkit.de/advisories/TKADV2008-012.txt</url>
+ </references>
+ <dates>
+ <discovery>2008-11-05</discovery>
+ <entry>2008-11-08</entry>
+ </dates>
+ </vuln>
+
<vuln vid="0e30e802-a9db-11dd-93a2-000bcdf0a03b">
<topic>opera -- multiple vulnerabilities</topic>
<affects>