Mageia alert MGASA-2015-0095 (vlc)
| From: | Mageia Updates <buildsystem-daemon@mageia.org> | |
| To: | updates-announce@ml.mageia.org | |
| Subject: | [updates-announce] MGASA-2015-0095: Updated vlc package fixes security vulnerability | |
| Date: | Thu, 5 Mar 2015 23:05:53 +0100 | |
| Message-ID: | <20150305220554.1362540646@valstar.mageia.org> |
MGASA-2015-0095 - Updated vlc package fixes security vulnerability Publication date: 05 Mar 2015 URL: http://advisories.mageia.org/MGASA-2015-0095.html Type: security Affected Mageia releases: 4 CVE: CVE-2014-6440 Description: Updated vlc packages (2.1.6) are an upgrade with some fixes. Some of the problems fixed upstream were already fixed by a previous Mageia update to VLC (see the link to MGASA-2015-0053). VLC versions before 2.1.5 contain a vulnerability in the transcode module that may allow a corrupted stream to overflow buffers on the heap. With a non-malicious input, this could lead to heap corruption and a crash. However, under the right circumstances, a malicious attacker could potentially use this vulnerability to hijack program execution, and on some platforms, execute arbitrary code (CVE-2014-6440) References: - https://bugs.mageia.org/show_bug.cgi?id=15384 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6... - http://openwall.com/lists/oss-security/2015/03/05/2 - http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6440 SRPMS: - 4/core/vlc-2.1.6-1.0.mga4 - 4/tainted/vlc-2.1.6-1.0.mga4.tainted
