Insufficient validation of ID3v2 tags

Bug #616510 reported by Rémi Denis-Courmont
262
This bug affects 1 person
Affects Status Importance Assigned to Milestone
VLC media player
Fix Released
High
Unassigned
vlc (Debian)
Fix Released
Unknown
vlc (Ubuntu)
Fix Released
Undecided
Unassigned
Jaunty
Won't Fix
Undecided
Unassigned
Karmic
Won't Fix
Undecided
Unassigned
Lucid
Fix Released
Undecided
Unassigned

Bug Description

Tags: patch

CVE References

visibility: private → public
Changed in vlc:
importance: Undecided → High
Changed in vlc (Ubuntu):
status: New → Confirmed
Changed in vlc:
milestone: none → 1.1.3
status: New → Fix Committed
Revision history for this message
Benjamin Drung (bdrung) wrote :

Here's the upstream patch for vlc 1.0.6.

Revision history for this message
Benjamin Drung (bdrung) wrote :

Here's my debdiff for lucid-security.

Changed in vlc (Ubuntu Lucid):
status: New → Confirmed
Revision history for this message
Benjamin Drung (bdrung) wrote :

We will fix the bug in maverick with uploading vlc 1.1.3 once it's released.

I have build the lucid-security package, upgraded it, and it still plays my videos.

Revision history for this message
Marc Deslauriers (mdeslaur) wrote :

Thanks for the debdiff Benjamin. Packages for lucid are being built now and should appear in the next day or so.

Unsubscribing ubuntu-security-sponsors since there are no more debdiffs to process.

Changed in vlc (Ubuntu Lucid):
status: Confirmed → Fix Committed
Revision history for this message
Launchpad Janitor (janitor) wrote :

This bug was fixed in the package vlc - 1.1.3-2ubuntu1

---------------
vlc (1.1.3-2ubuntu1) maverick; urgency=low

  * Merge from Debian experimental, remaining changes:
    - build and install the libx264 plugin

vlc (1.1.3-2) experimental; urgency=low

  [ Christophe Mutricy ]
  * Depends on xulrunner-dev >= 1.9.2
  * Activate VA-API (Closes: #587792, LP: #539406)

  [ Benjamin Drung ]
  * Switch to dh7.
  * Move libavcodec plugin from vlc-nox to vlc.
  * Add Xb-Npp header to mozilla-plugin-vlc package. (Not doing anything
    on Debian at the moment, see #484010)
  * Add apport hook to include more VLC dependencies in bug reports and
    install it on Ubuntu.

vlc (1.1.3-1) unstable; urgency=medium

  [ Benjamin Drung ]
  * New upstream release.
    + Fix insufficient input validation in TagLib plugin.
      (VideoLAN-SA-1004, CVE-2010-2937) (Closes: #592669, LP: #616510)
    + Set urgency to medium
  * 502_xulrunner_191.diff: Shorten, split into two parts, and refresh it.
  * Drop 102_dejavu_font.diff and depend on ttf-freefont instead of ttf-
    dejavu-core. ttf-freefont is very likely to be present on a Debian
    box, because cups depends on it.
  * Drop 501_decrease_alsa_buffer.diff. The pulseaudio output module has
    a higher priority than the ALSA output plugin and should be used on
    pulseaudio systems.

  [ Reinhard Tartler ]
  * add DM-Upload-Allowed field to debian/control
 -- Benjamin Drung <email address hidden> Thu, 19 Aug 2010 23:16:03 +0200

Changed in vlc (Ubuntu):
status: Confirmed → Fix Released
Revision history for this message
Launchpad Janitor (janitor) wrote :

This bug was fixed in the package vlc - 1.0.6-1ubuntu1.2

---------------
vlc (1.0.6-1ubuntu1.2) lucid-security; urgency=low

  * SECURITY UPDATE: Insufficient input validation in VLC TagLib plugin
    (LP: #616510).
    - debian/patches/CVE-2010-2937.patch: fix NULL deferences after dynamic
      cast, thanks to Lukáš Lalinský
    - CVE-2010-2937
 -- Benjamin Drung <email address hidden> Tue, 17 Aug 2010 17:14:14 +0200

Changed in vlc (Ubuntu Lucid):
status: Fix Committed → Fix Released
Revision history for this message
Alex Valavanis (valavanisalex) wrote :

Jaunty reached end-of-life on 23 October 2010. The bug is marked as fixed in later versions of Ubuntu

Changed in vlc (Ubuntu Jaunty):
status: New → Won't Fix
Changed in vlc:
status: Fix Committed → Fix Released
Changed in vlc (Debian):
status: Unknown → Fix Released
Revision history for this message
Jamie Strandboge (jdstrand) wrote :

Thank you for reporting this bug to Ubuntu. karmic has reached EOL
(End of Life) and is no longer supported. As a result, this bug
against karmic is being marked "Won't Fix". Please see
https://wiki.ubuntu.com/Releases for currently supported Ubuntu
releases.

Please feel free to report any other bugs you may find.

Changed in vlc (Ubuntu Karmic):
status: New → Won't Fix
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.