[vlc-devel] commit: Update news on fixed CVEs. (Pavlov Konstantin )

git version control git at videolan.org
Sat May 17 01:30:06 CEST 2008


vlc | branch: 0.8.6-bugfix | Pavlov Konstantin <thresh at videolan.org> | Sat May 17 03:31:17 2008 +0400| [b8708ee9402811d1e7c2b6fd77c9bffc5aa9823a]

Update news on fixed CVEs.

> http://git.videolan.org/gitweb.cgi/vlc.git/?a=commit;h=b8708ee9402811d1e7c2b6fd77c9bffc5aa9823a
---

 NEWS |    2 ++
 1 files changed, 2 insertions(+), 0 deletions(-)

diff --git a/NEWS b/NEWS
index ed1b896..a1ea137 100644
--- a/NEWS
+++ b/NEWS
@@ -5,6 +5,8 @@ Security updates:
  * Removed VLC variable settings from Mozilla and ActiveX (CVE-2007-6683)
  * Removed loading plugins from the current directory (CVE-2008-2147)
  * Updated libpng on Windows and Mac OS X (CVE-2008-1382)
+ * Fixed libid3tag denial of service (CVE-2008-2109)
+ * Fixed libvorbis vulnerabilities (CVE-2008-1419, CVE-2008-1420, CVE-2008-1423)
 
 Various bugfixes:
  * Fixed various memory leaks, improving stability when running as a server




More information about the vlc-devel mailing list