Bug#737534: vlc: unsafe use of libtar

2014-08-16 Thread Jean-Baptiste Kempf
On 16 Aug, Reinhard Tartler wrote : > Control: tag -1 upstream > > On Mon, Feb 3, 2014 at 10:08 AM, Raphael Geissert wrote: > > Package: vlc > > Severity: important > > Tags: security > > > > Hi, > > > > vlc uses libtar to unpack skins, however, its use on untrusted data > > exposes it to CVE-201

Bug#737534: vlc: unsafe use of libtar

2014-08-16 Thread Reinhard Tartler
Control: tag -1 upstream On Mon, Feb 3, 2014 at 10:08 AM, Raphael Geissert wrote: > Package: vlc > Severity: important > Tags: security > > Hi, > > vlc uses libtar to unpack skins, however, its use on untrusted data > exposes it to CVE-2013-4420 (#731860). > > Changing the behaviour of libtar app

Processed: Re: Bug#737534: vlc: unsafe use of libtar

2014-08-16 Thread Debian Bug Tracking System
Processing control commands: > tag -1 upstream Bug #737534 [vlc] vlc: unsafe use of libtar Added tag(s) upstream. -- 737534: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=737534 Debian Bug Tracking System Contact ow...@bugs.debian.org with problems ___

Bug#737534: vlc: unsafe use of libtar

2014-02-03 Thread Raphael Geissert
Package: vlc Severity: important Tags: security Hi, vlc uses libtar to unpack skins, however, its use on untrusted data exposes it to CVE-2013-4420 (#731860). Changing the behaviour of libtar appears to be problematic because some applications have relied on the, lack of, path sanitation (cf. ht