View Git repositories
Name Status Last Modified Last Commit
lp://qastaging/ubuntu/wily/vlc 1 Development 2015-05-06 04:25:42 UTC
120. * debian/vlc.postinst: Fix directory ...

Author: Benjamin Drung
Revision Date: 2012-10-04 20:59:21 UTC

* debian/vlc.postinst: Fix directory to symlink upgrade in postinst.
  Thanks to David Prévot <taffit@debian.org> (Closes: #687657)
* debian/vlc.preinst: Remove insufficient fix to #613121 (similar issue).
  Thanks to David Prévot for the patch.
* Cherry-pick fix for VLC hang caused by the notify plugin. (Closes: #662628,
  LP: #970447)
* Drop alternative dependency on transitional ttf-freefont.

lp://qastaging/ubuntu/vivid/vlc 2 Mature 2014-10-27 01:15:43 UTC
120. * debian/vlc.postinst: Fix directory ...

Author: Benjamin Drung
Revision Date: 2012-10-04 20:59:21 UTC

* debian/vlc.postinst: Fix directory to symlink upgrade in postinst.
  Thanks to David Prévot <taffit@debian.org> (Closes: #687657)
* debian/vlc.preinst: Remove insufficient fix to #613121 (similar issue).
  Thanks to David Prévot for the patch.
* Cherry-pick fix for VLC hang caused by the notify plugin. (Closes: #662628,
  LP: #970447)
* Drop alternative dependency on transitional ttf-freefont.

lp://qastaging/ubuntu/utopic/vlc 2 Mature 2014-04-25 04:39:33 UTC
120. * debian/vlc.postinst: Fix directory ...

Author: Benjamin Drung
Revision Date: 2012-10-04 20:59:21 UTC

* debian/vlc.postinst: Fix directory to symlink upgrade in postinst.
  Thanks to David Prévot <taffit@debian.org> (Closes: #687657)
* debian/vlc.preinst: Remove insufficient fix to #613121 (similar issue).
  Thanks to David Prévot for the patch.
* Cherry-pick fix for VLC hang caused by the notify plugin. (Closes: #662628,
  LP: #970447)
* Drop alternative dependency on transitional ttf-freefont.

lp://qastaging/ubuntu/trusty/vlc 2 Mature 2013-10-18 16:26:42 UTC
120. * debian/vlc.postinst: Fix directory ...

Author: Benjamin Drung
Revision Date: 2012-10-04 20:59:21 UTC

* debian/vlc.postinst: Fix directory to symlink upgrade in postinst.
  Thanks to David Prévot <taffit@debian.org> (Closes: #687657)
* debian/vlc.preinst: Remove insufficient fix to #613121 (similar issue).
  Thanks to David Prévot for the patch.
* Cherry-pick fix for VLC hang caused by the notify plugin. (Closes: #662628,
  LP: #970447)
* Drop alternative dependency on transitional ttf-freefont.

lp://qastaging/ubuntu/saucy/vlc 2 Mature 2013-04-26 11:13:46 UTC
120. * debian/vlc.postinst: Fix directory ...

Author: Benjamin Drung
Revision Date: 2012-10-04 20:59:21 UTC

* debian/vlc.postinst: Fix directory to symlink upgrade in postinst.
  Thanks to David Prévot <taffit@debian.org> (Closes: #687657)
* debian/vlc.preinst: Remove insufficient fix to #613121 (similar issue).
  Thanks to David Prévot for the patch.
* Cherry-pick fix for VLC hang caused by the notify plugin. (Closes: #662628,
  LP: #970447)
* Drop alternative dependency on transitional ttf-freefont.

lp://qastaging/ubuntu/raring/vlc 2 Mature 2012-10-19 06:52:05 UTC
120. * debian/vlc.postinst: Fix directory ...

Author: Benjamin Drung
Revision Date: 2012-10-04 20:59:21 UTC

* debian/vlc.postinst: Fix directory to symlink upgrade in postinst.
  Thanks to David Prévot <taffit@debian.org> (Closes: #687657)
* debian/vlc.preinst: Remove insufficient fix to #613121 (similar issue).
  Thanks to David Prévot for the patch.
* Cherry-pick fix for VLC hang caused by the notify plugin. (Closes: #662628,
  LP: #970447)
* Drop alternative dependency on transitional ttf-freefont.

lp://qastaging/ubuntu/quantal/vlc bug 2 Mature 2012-10-05 12:53:10 UTC
120. * debian/vlc.postinst: Fix directory ...

Author: Benjamin Drung
Revision Date: 2012-10-04 20:59:21 UTC

* debian/vlc.postinst: Fix directory to symlink upgrade in postinst.
  Thanks to David Prévot <taffit@debian.org> (Closes: #687657)
* debian/vlc.preinst: Remove insufficient fix to #613121 (similar issue).
  Thanks to David Prévot for the patch.
* Cherry-pick fix for VLC hang caused by the notify plugin. (Closes: #662628,
  LP: #970447)
* Drop alternative dependency on transitional ttf-freefont.

lp://qastaging/ubuntu/precise-updates/vlc 2 Mature 2012-08-02 21:55:39 UTC
115. * New bug-fixing upstream release (LP...

Author: Benjamin Drung
Revision Date: 2012-07-24 00:44:39 UTC

* New bug-fixing upstream release (LP: #1025713).
* SECURITY UPDATE: Heap-based buffer overflow in the Ogg_DecodePacket function
  in the OGG demuxer (modules/demux/ogg.c) in VideoLAN VLC media player before
  2.0.2 allows remote attackers to cause a denial of service (application
  crash) and possibly execute arbitrary code via a crafted OGG file.
  - CVE-2012-3377

lp://qastaging/ubuntu/precise-security/vlc 2 Mature 2012-08-02 21:55:23 UTC
115. * New bug-fixing upstream release (LP...

Author: Benjamin Drung
Revision Date: 2012-07-24 00:44:39 UTC

* New bug-fixing upstream release (LP: #1025713).
* SECURITY UPDATE: Heap-based buffer overflow in the Ogg_DecodePacket function
  in the OGG demuxer (modules/demux/ogg.c) in VideoLAN VLC media player before
  2.0.2 allows remote attackers to cause a denial of service (application
  crash) and possibly execute arbitrary code via a crafted OGG file.
  - CVE-2012-3377

lp://qastaging/ubuntu/precise-proposed/vlc bug 2 Mature 2012-07-25 14:40:26 UTC
115. * New bug-fixing upstream release (LP...

Author: Benjamin Drung
Revision Date: 2012-07-24 00:44:39 UTC

* New bug-fixing upstream release (LP: #1025713).
* SECURITY UPDATE: Heap-based buffer overflow in the Ogg_DecodePacket function
  in the OGG demuxer (modules/demux/ogg.c) in VideoLAN VLC media player before
  2.0.2 allows remote attackers to cause a denial of service (application
  crash) and possibly execute arbitrary code via a crafted OGG file.
  - CVE-2012-3377

lp://qastaging/ubuntu/precise/vlc bug 2 Mature 2012-03-30 01:56:37 UTC
114. Add missing Breaks and Replaces for m...

Author: Benjamin Drung
Revision Date: 2012-03-30 01:56:37 UTC

Add missing Breaks and Replaces for moving the documentation from vlc-data
away from /usr/share/doc/vlc before converting the directory into a symlink.
(Closes: #665743)

lp://qastaging/~nik90/ubuntu/precise/vlc/keywords bug(Has a merge proposal) 1 Development 2012-02-29 01:39:15 UTC
109. Added keywords to the desktop file ac...

Author: <email address hidden>
Revision Date: 2012-02-29 01:36:12 UTC

Added keywords to the desktop file accordingto the new specifications

lp://qastaging/ubuntu/oneiric-updates/vlc 2 Mature 2011-10-27 05:26:33 UTC
36. No-change backport to oneiric to fix ...

Author: Benjamin Drung
Revision Date: 2011-10-19 21:18:35 UTC

No-change backport to oneiric to fix PulseAudio support and other bugs.

lp://qastaging/ubuntu/oneiric-proposed/vlc 2 Mature 2011-10-20 17:23:10 UTC
36. No-change backport to oneiric to fix ...

Author: Benjamin Drung
Revision Date: 2011-10-19 21:18:35 UTC

No-change backport to oneiric to fix PulseAudio support and other bugs.

lp://qastaging/ubuntu/oneiric/vlc bug 2 Mature 2011-09-03 22:04:14 UTC
99. Rebuild to drop dependencies on super...

Author: Matthias Klose
Revision Date: 2011-09-03 22:04:14 UTC

Rebuild to drop dependencies on superseded libraries.

lp://qastaging/ubuntu/lucid-updates/vlc bug 2 Mature 2011-07-22 12:07:18 UTC
79. * SECURITY UPDATE: Heap overflow in A...

Author: Benjamin Drung
Revision Date: 2011-07-18 16:15:19 UTC

* SECURITY UPDATE: Heap overflow in AVI demuxer (LP: #807488)
  - debian/patches/CVE-2011-2588.patch: AVI: fix heap buffer overflow,
    thanks to Rémi Denis-Courmont
  - CVE-2011-2588
  - VideoLAN-SA-1106

lp://qastaging/ubuntu/maverick-updates/vlc bug 2 Mature 2011-07-22 12:07:13 UTC
88. * SECURITY UPDATE: Heap overflow in R...

Author: Benjamin Drung
Revision Date: 2011-07-18 16:10:28 UTC

* SECURITY UPDATE: Heap overflow in RealMedia demuxer (LP: #807486)
  - debian/patches/CVE-2011-2587.patch: real: fix heap buffer overflow,
    thanks to Rémi Denis-Courmont
  - CVE-2011-2587
  - VideoLAN-SA-1105
* SECURITY UPDATE: Heap overflow in AVI demuxer (LP: #807488)
  - debian/patches/CVE-2011-2588.patch: AVI: fix heap buffer overflow,
    thanks to Rémi Denis-Courmont
  - CVE-2011-2588
  - VideoLAN-SA-1106

lp://qastaging/ubuntu/natty-updates/vlc bug 2 Mature 2011-07-22 12:07:02 UTC
96. * SECURITY UPDATE: Heap overflow in R...

Author: Benjamin Drung
Revision Date: 2011-07-18 15:48:36 UTC

* SECURITY UPDATE: Heap overflow in RealMedia demuxer (LP: #807486)
  - debian/patches/CVE-2011-2587.patch: real: fix heap buffer overflow,
    thanks to Rémi Denis-Courmont
  - CVE-2011-2587
  - VideoLAN-SA-1105
* SECURITY UPDATE: Heap overflow in AVI demuxer (LP: #807488)
  - debian/patches/CVE-2011-2588.patch: AVI: fix heap buffer overflow,
    thanks to Rémi Denis-Courmont
  - CVE-2011-2588
  - VideoLAN-SA-1106

lp://qastaging/ubuntu/maverick-security/vlc bug 2 Mature 2011-07-22 12:06:59 UTC
88. * SECURITY UPDATE: Heap overflow in R...

Author: Benjamin Drung
Revision Date: 2011-07-18 16:10:28 UTC

* SECURITY UPDATE: Heap overflow in RealMedia demuxer (LP: #807486)
  - debian/patches/CVE-2011-2587.patch: real: fix heap buffer overflow,
    thanks to Rémi Denis-Courmont
  - CVE-2011-2587
  - VideoLAN-SA-1105
* SECURITY UPDATE: Heap overflow in AVI demuxer (LP: #807488)
  - debian/patches/CVE-2011-2588.patch: AVI: fix heap buffer overflow,
    thanks to Rémi Denis-Courmont
  - CVE-2011-2588
  - VideoLAN-SA-1106

lp://qastaging/ubuntu/lucid-security/vlc bug 2 Mature 2011-07-18 16:15:19 UTC
79. * SECURITY UPDATE: Heap overflow in A...

Author: Benjamin Drung
Revision Date: 2011-07-18 16:15:19 UTC

* SECURITY UPDATE: Heap overflow in AVI demuxer (LP: #807488)
  - debian/patches/CVE-2011-2588.patch: AVI: fix heap buffer overflow,
    thanks to Rémi Denis-Courmont
  - CVE-2011-2588
  - VideoLAN-SA-1106

lp://qastaging/ubuntu/natty-security/vlc bug 2 Mature 2011-07-18 15:48:36 UTC
95. * SECURITY UPDATE: Heap overflow in R...

Author: Benjamin Drung
Revision Date: 2011-07-18 15:48:36 UTC

* SECURITY UPDATE: Heap overflow in RealMedia demuxer (LP: #807486)
  - debian/patches/CVE-2011-2587.patch: real: fix heap buffer overflow,
    thanks to Rémi Denis-Courmont
  - CVE-2011-2587
  - VideoLAN-SA-1105
* SECURITY UPDATE: Heap overflow in AVI demuxer (LP: #807488)
  - debian/patches/CVE-2011-2588.patch: AVI: fix heap buffer overflow,
    thanks to Rémi Denis-Courmont
  - CVE-2011-2588
  - VideoLAN-SA-1106

lp://qastaging/ubuntu/natty-proposed/vlc bug 1 Development 2011-06-16 16:23:11 UTC
95. * Backport PulseAudio output plugin r...

Author: Benjamin Drung
Revision Date: 2011-06-14 03:04:10 UTC

* Backport PulseAudio output plugin rewrite to fix memory leak. (LP: #743323)
* ASX: fix NULL derefence (LP: #785979)
* Qt: undo the FSC/KDE workaround (LP: #774581)
* Add Firefox 4 compatibility (LP: #722690)

lp://qastaging/ubuntu/natty/vlc bug 2 Mature 2011-04-14 17:24:13 UTC
93. * Merge from Debian unstable (LP: #76...

Author: Benjamin Drung
Revision Date: 2011-04-14 11:51:25 UTC

* Merge from Debian unstable (LP: #760510), remaining changes:
  - build and install the libx264 plugin

lp://qastaging/ubuntu/maverick-proposed/vlc bug 2 Mature 2010-11-24 00:28:41 UTC
83. Fixed wrong aspect ratio in transcode...

Author: Nicola Ferralis
Revision Date: 2010-11-19 01:12:25 UTC

Fixed wrong aspect ratio in transcoded image from webcam. (LP: #672304)

lp://qastaging/ubuntu/maverick/vlc bug 2 Mature 2010-09-05 02:20:35 UTC
82. * Merge from Debian experimental, rem...

Author: Benjamin Drung
Revision Date: 2010-09-05 02:20:35 UTC

* Merge from Debian experimental, remaining changes:
  - build and install the libx264 plugin

lp://qastaging/ubuntu/lucid-proposed/vlc bug 2 Mature 2010-05-07 12:34:15 UTC
73. * debian/vlc{,-nox}.install: - Move...

Author: Alessio Treglia
Revision Date: 2010-05-04 14:17:27 UTC

* debian/vlc{,-nox}.install:
  - Move libx264 plugin from vlc to vlc-nox (LP: #575054).
* debian/control:
  - Adjust vlc-nox Replaces field properly.

lp://qastaging/ubuntu/lucid/vlc bug 1 Development 2010-04-23 12:16:15 UTC
72. * Merge from Debian unstable, remaini...

Author: Benjamin Drung
Revision Date: 2010-04-23 12:16:15 UTC

* Merge from Debian unstable, remaining changes:
  - build and install the libx264 plugin
  - add Xb-Npp header to vlc package
  - Add patches 519-526 to fix FTBFS with xulruner-1.9.2 from upstream
  - Add 600-drop-OJI-xul-192.patch to drop OJI support as xulrunner-1.9.2 on
    Linux doesn't support it
  - Add apport hook to include more vlc dependencies in bug reports
  - Drop --sourcedir=debian/tmp from dh_install to install apport hook
* Drop 527-spanish-desktop.patch (merged upstream).

lp://qastaging/ubuntu/karmic-updates/vlc 2 Mature 2010-01-10 11:17:55 UTC
63. * add libupnp3-dev as build-dep to en...

Author: Peter Meiser
Revision Date: 2009-11-12 17:32:43 UTC

* add libupnp3-dev as build-dep to enable UPnP module (LP: #481448)
* add libcddb2-dev as build-dep to enable CDDB in the CDDA
  module (LP: #439131)
* add libxcb-keysyms1-dev as build-dep to enable globalhotkeys
  module (LP: #439077)

lp://qastaging/ubuntu/karmic-proposed/vlc bug 2 Mature 2010-01-08 15:33:26 UTC
63. * add libupnp3-dev as build-dep to en...

Author: Peter Meiser
Revision Date: 2009-11-12 17:32:43 UTC

* add libupnp3-dev as build-dep to enable UPnP module (LP: #481448)
* add libcddb2-dev as build-dep to enable CDDB in the CDDA
  module (LP: #439131)
* add libxcb-keysyms1-dev as build-dep to enable globalhotkeys
  module (LP: #439077)

lp://qastaging/ubuntu/jaunty/vlc 2 Mature 2010-01-08 15:32:23 UTC
54. * Merge from debian which includes a ...

Author: Reinhard Tartler
Revision Date: 2009-04-18 19:52:57 UTC

* Merge from debian which includes a small security fix.
* Adjusted Vcs fields to point to pkg-multimedia's git branch. The
  package is maintained in the 'jaunty' branch.
* Remaining changes to debian:
  - build against libxul-dev instead of iceape-dev
  - build against libass-dev and libx264-dev
  - build against and install libx264 plugin
  - add Xb-Npp header to vlc package
  - debian/patches/301_DVD_media.diff: Change %U to %f
     in VLC .desktop file, cf LP #275043
  - Remove arts from dependencies. (LP: #320915)
    - debian/control:
      - Remove libarts1-dev from build depends
      - Don't build package vlc-plugin-arts
      - Remove all notions of vlc-plugin-arts from packages descriptions
    - debian/rules:
      - Remove --enable-arts from confflags
    - Delete debian/vlc-plugin-arts.install
    - Delete debian/vlc-plugin-arts.links

lp://qastaging/ubuntu/intrepid/vlc 2 Mature 2010-01-08 15:32:02 UTC
48. * link vlc to unicode enabled curses ...

Author: Reinhard Tartler
Revision Date: 2008-10-13 21:47:13 UTC

* link vlc to unicode enabled curses library. Thanks to Rafaël Carré for
  reporting.(LP: #282644)
* enable emedded video (LP: #282582)
* Autodetect screen while using Xinerama to toggle fullscreen (LP: #115419)

lp://qastaging/ubuntu/hardy/vlc 2 Mature 2010-01-08 15:31:37 UTC
40. * debian/control: Make vlc-plugin-pul...

Author: Luke Yelavich
Revision Date: 2008-04-12 09:23:55 UTC

* debian/control: Make vlc-plugin-pulse a dependency of vlc, to enable pulseaudio
  by default. (LP: #208579)
* debian/patches/demuxer-fix.diff: Patch to fix FTBFS, thanks to Gentoo bug
  214809.

lp://qastaging/ubuntu/gutsy/vlc 1 Development 2010-01-08 15:31:18 UTC
30. * Add patch 030_fix_exec_field_code: ...

Author: Cesare Tirabassi
Revision Date: 2007-10-08 23:41:44 UTC

* Add patch 030_fix_exec_field_code:
  - fix opening multiple files leads to multiple instances (LP: #124712)

lp://qastaging/ubuntu/feisty/vlc 1 Development 2010-01-08 15:30:53 UTC
24. debian/control: Revert back to buildi...

Author: Luke Yelavich
Revision Date: 2007-03-20 16:32:06 UTC

debian/control: Revert back to building against libwxgtk2.6-dev
(Closes LP: #91248)

lp://qastaging/ubuntu/edgy/vlc 1 Development 2010-01-08 15:30:24 UTC
20. * Merge from Debian unstable, remaini...

Author: Daniel T Chen
Revision Date: 2006-10-18 01:31:36 UTC

* Merge from Debian unstable, remaining Ubuntu changes:
  - debian/control: Don't build-depend on libtwolame-dev, a newer
    version of libcaca-dev, or linux-kernel-headers (Ubuntu Edgy
    does not have them),
  - debian/patches/001_1008snap.{fixes,translations}.diff: Remove,
    this is a new upstream version, fixes FTBFS on translations,
  - debian/rules: Use Ubuntu-specific configure options (firefox).
* New upstream snapshot fixes wxvlc not stopping when 'close
  button' is clicked (Closes Ubuntu: #54630).
* New upstream snapshot has more robust x264 support
  (Closes: Ubuntu #62217).
* Segfault when using HTTP interface was fixed in
  0.8.6-svn20060918.debian-1ubuntu4 (Closes Ubuntu: #63833).
* New upstream snapshot should resolve issues with skins2/wxw
  interfaces (Closes: Ubuntu #64975).

lp://qastaging/ubuntu/dapper/vlc 2 Mature 2010-01-08 15:30:00 UTC
13. "'Time to race', she said, 'Race the ...

Author: Daniel T Chen
Revision Date: 2006-05-23 03:42:19 UTC

"'Time to race', she said, 'Race the downhill'."

* Add debian/patches/24_prefs_stacking_fix, fixing stacking in
  Preferences dialog. Taken from upstream svn changeset 13795, thanks
  to Bruce Cowan (Closes: Malone #31891).
* Demote ttf-freefont, ttf-thryomanes to Suggests as the former
  provides bad metrics for Thai. See Debian #362071 for additional
  information.
* Don't use gcc-snapshot as the compiler. See Debian #361729 for more
  information.
* Make vlc.desktop HIG-compliant.
* Rebuild against new libebml-dev and libmatroska-dev, fixing crashes
  with Matroska files (Closes: Malone #29644).
* Use our own faad2 and x264, fixing garbled graphics (Closes: Malone
  #28539). Please see Debian #365389 if the inclusion of these
  libraries stirs your ire.

lp://qastaging/ubuntu/breezy/vlc 1 Development 2010-01-08 15:29:46 UTC
6. * debian/: + Let's not clobber our ...

Author: Daniel T Chen
Revision Date: 2005-10-11 19:39:59 UTC

* debian/:
  + Let's not clobber our wxWidgets dialog completely by "chomping at
    the SVN-trunk bit". There are way too many necessary patches for
    wxWidgets. Thus, replace the libwxgtk2.6-dev Build-Depends with
    libwxgtk2.4-dev. At least playlist loading works again. Finally
    closes: #3062, #3064.
  + Disable Matroska support, since the version in the archive is too
    old to be useful on this build.
  + "I hate you libpostproc-dev", or the real reason ffmpeg needs to
    be included in the first place.

lp://qastaging/ubuntu/hoary/vlc 1 Development 2010-01-08 15:29:36 UTC
4. Really fix the .desktop entries.

Author: Daniel T Chen
Revision Date: 2005-03-27 22:05:30 UTC

Really fix the .desktop entries.

lp://qastaging/ubuntu/warty/vlc 1 Development 2010-01-08 15:29:25 UTC
3. extras/ffmpeg/configure: fixed HPPA a...

Author: Sam Hocevar
Revision Date: 2004-06-25 11:55:33 UTC

extras/ffmpeg/configure: fixed HPPA architecture detection.

lp://qastaging/ubuntu/karmic/vlc bug 1 Development 2009-10-19 21:19:26 UTC
62. PulseAudio: higher priority than ALSA...

Author: Reinhard Tartler
Revision Date: 2009-10-19 21:19:26 UTC

PulseAudio: higher priority than ALSA, LP: #402018

lp://qastaging/ubuntu/intrepid-security/vlc bug 2 Mature 2009-07-14 12:20:28 UTC
50. * SECURITY UPDATE: Arbitrary code exe...

Author: Marc Deslauriers
Revision Date: 2009-06-28 12:13:15 UTC

* SECURITY UPDATE: Arbitrary code execution via stack-based overflow in
  the Ty demux plugin (LP: #285922)
  - debian/patches/901_CVE-2008-4654.patch: don't overflow mst_buf in
    modules/demux/ty.c
  - CVE-2008-4654
* SECURITY UPDATE: Arbitrary code execution via integer overflows in
  the Ty demux plugin (LP: #285922)
  - debian/patches/902_CVE-2008-4686.patch: make some variables unsigned
    in modules/demux/ty.c so they don't overflow.
  - CVE-2008-4686
* SECURITY UPDATE: Arbitrary code execution via stack-based buffer
  overflow via invalid RealText subtitle file.
  - debian/patches/903_CVE-2008-5036.patch: limit sscanf sizes in
    modules/demux/subtitle.c
  - CVE-2008-5036
* SECURITY UPDATE: Arbitrary code execution via heap-based buffer
  overflow via malformed RealMedia file.
  - debian/patches/904_CVE-2008-5276.patch: replace malloc with calloc in
    modules/demux/real.c
  - CVE-2008-5276
* SECURITY UPDATE: Denial of service via long input argument.
  - debian/patches/905_CVE-2009-1045.patch: make sure we can't overflow
    psz_dup in src/input/input.c
  - CVE-2009-1045

lp://qastaging/ubuntu/hardy-security/vlc bug 2 Mature 2009-07-14 12:20:25 UTC
43. * SECURITY UPDATE: aribrary code exec...

Author: Marc Deslauriers
Revision Date: 2009-06-28 10:11:40 UTC

* SECURITY UPDATE: aribrary code execution via invalid cue image file.
  (LP: #294243)
  - debian/patches/042_CVE-2008-5032.diff: make sure we don't overflow
    p_sectors in modules/access/vcd/cdrom.c
  - CVE-2008-5032

lp://qastaging/ubuntu/intrepid-updates/vlc 2 Mature 2009-07-14 12:19:15 UTC
50. * SECURITY UPDATE: Arbitrary code exe...

Author: Marc Deslauriers
Revision Date: 2009-06-28 12:13:15 UTC

* SECURITY UPDATE: Arbitrary code execution via stack-based overflow in
  the Ty demux plugin (LP: #285922)
  - debian/patches/901_CVE-2008-4654.patch: don't overflow mst_buf in
    modules/demux/ty.c
  - CVE-2008-4654
* SECURITY UPDATE: Arbitrary code execution via integer overflows in
  the Ty demux plugin (LP: #285922)
  - debian/patches/902_CVE-2008-4686.patch: make some variables unsigned
    in modules/demux/ty.c so they don't overflow.
  - CVE-2008-4686
* SECURITY UPDATE: Arbitrary code execution via stack-based buffer
  overflow via invalid RealText subtitle file.
  - debian/patches/903_CVE-2008-5036.patch: limit sscanf sizes in
    modules/demux/subtitle.c
  - CVE-2008-5036
* SECURITY UPDATE: Arbitrary code execution via heap-based buffer
  overflow via malformed RealMedia file.
  - debian/patches/904_CVE-2008-5276.patch: replace malloc with calloc in
    modules/demux/real.c
  - CVE-2008-5276
* SECURITY UPDATE: Denial of service via long input argument.
  - debian/patches/905_CVE-2009-1045.patch: make sure we can't overflow
    psz_dup in src/input/input.c
  - CVE-2009-1045

lp://qastaging/ubuntu/gutsy-security/vlc bug 1 Development 2009-07-14 12:19:12 UTC
32. * SECURITY UPDATE: (LP: #207284) + d...

Author: Emanuele Gentili
Revision Date: 2008-04-01 02:33:08 UTC

* SECURITY UPDATE: (LP: #207284)
 + debian/patches/031_CVE-2008-1489.diff
  - Integer overflow in the MP4_ReadBox_rdrf function in libmp4.c allows
    remote attackers to cause a denial of service (crash) and possibly
    execute arbitrary code via a crafted MP4 RDRF box that triggers a
    heap-based buffer overflow.

* References
 + http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2008-1489
 + http://trac.videolan.org/vlc/changeset/09572892df7e72c0d4e598c0b5e076cf330d8b0a

lp://qastaging/ubuntu/hardy-updates/vlc 2 Mature 2009-07-14 12:18:43 UTC
43. * SECURITY UPDATE: aribrary code exec...

Author: Marc Deslauriers
Revision Date: 2009-06-28 10:11:40 UTC

* SECURITY UPDATE: aribrary code execution via invalid cue image file.
  (LP: #294243)
  - debian/patches/042_CVE-2008-5032.diff: make sure we don't overflow
    p_sectors in modules/access/vcd/cdrom.c
  - CVE-2008-5032

lp://qastaging/ubuntu/feisty-security/vlc bug 1 Development 2009-07-14 12:18:09 UTC
26. * SECURITY UPDATE: (LP: #207284) + d...

Author: Emanuele Gentili
Revision Date: 2008-04-01 02:58:30 UTC

* SECURITY UPDATE: (LP: #207284)
 + debian/patches/031_CVE-2008-1489.diff
  - Integer overflow in the MP4_ReadBox_rdrf function in libmp4.c allows
    remote attackers to cause a denial of service (crash) and possibly
    execute arbitrary code via a crafted MP4 RDRF box that triggers a
    heap-based buffer overflow.

* References
 + http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2008-1489
 + http://trac.videolan.org/vlc/changeset/09572892df7e72c0d4e598c0b5e076cf330d8b0a

lp://qastaging/ubuntu/gutsy-updates/vlc 1 Development 2009-07-14 12:17:52 UTC
32. * SECURITY UPDATE: (LP: #207284) + d...

Author: Emanuele Gentili
Revision Date: 2008-04-01 02:33:08 UTC

* SECURITY UPDATE: (LP: #207284)
 + debian/patches/031_CVE-2008-1489.diff
  - Integer overflow in the MP4_ReadBox_rdrf function in libmp4.c allows
    remote attackers to cause a denial of service (crash) and possibly
    execute arbitrary code via a crafted MP4 RDRF box that triggers a
    heap-based buffer overflow.

* References
 + http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2008-1489
 + http://trac.videolan.org/vlc/changeset/09572892df7e72c0d4e598c0b5e076cf330d8b0a

lp://qastaging/ubuntu/feisty-updates/vlc 1 Development 2009-07-14 12:16:59 UTC
26. * SECURITY UPDATE: (LP: #207284) + d...

Author: Emanuele Gentili
Revision Date: 2008-04-01 02:58:30 UTC

* SECURITY UPDATE: (LP: #207284)
 + debian/patches/031_CVE-2008-1489.diff
  - Integer overflow in the MP4_ReadBox_rdrf function in libmp4.c allows
    remote attackers to cause a denial of service (crash) and possibly
    execute arbitrary code via a crafted MP4 RDRF box that triggers a
    heap-based buffer overflow.

* References
 + http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2008-1489
 + http://trac.videolan.org/vlc/changeset/09572892df7e72c0d4e598c0b5e076cf330d8b0a

lp://qastaging/ubuntu/edgy-security/vlc bug 1 Development 2009-07-14 12:16:18 UTC
22. * SECURITY UPDATE: - debian/patche...

Author: Emanuele Gentili
Revision Date: 2008-03-11 20:25:38 UTC

* SECURITY UPDATE:
  - debian/patches/CVE-2008-0984.patch (LP: #195949)
   + VLC media player's MPEG-4 file format parser (a.k.a. the MP4 demuxer)
     suffers from an arbitrary memory overwrite vulnerability when using
     crash the player instance.

* References
  - http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0984
  - http://www.videolan.org/security/sa0802.html

lp://qastaging/ubuntu/edgy-backports/vlc 1 Development 2009-07-14 12:16:09 UTC
21. Automated backport upload; no source ...

Author: John Dong
Revision Date: 2007-03-07 23:12:48 UTC

Automated backport upload; no source changes.

lp://qastaging/ubuntu/edgy-updates/vlc 1 Development 2009-07-14 12:15:41 UTC
22. * SECURITY UPDATE: - debian/patche...

Author: Emanuele Gentili
Revision Date: 2008-03-11 20:25:38 UTC

* SECURITY UPDATE:
  - debian/patches/CVE-2008-0984.patch (LP: #195949)
   + VLC media player's MPEG-4 file format parser (a.k.a. the MP4 demuxer)
     suffers from an arbitrary memory overwrite vulnerability when using
     crash the player instance.

* References
  - http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0984
  - http://www.videolan.org/security/sa0802.html

lp://qastaging/ubuntu/dapper-security/vlc bug 2 Mature 2009-07-14 12:15:33 UTC
16. * SECURITY UPDATE: (LP: #207284) + d...

Author: Emanuele Gentili
Revision Date: 2008-04-01 03:48:00 UTC

* SECURITY UPDATE: (LP: #207284)
 + debian/patches/031_CVE-2008-1489.dpatch
  - Integer overflow in the MP4_ReadBox_rdrf function in libmp4.c allows
    remote attackers to cause a denial of service (crash) and possibly
    execute arbitrary code via a crafted MP4 RDRF box that triggers a
    heap-based buffer overflow.

* References
 + http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2008-1489
 + http://trac.videolan.org/vlc/changeset/09572892df7e72c0d4e598c0b5e076cf330d8b0a

lp://qastaging/ubuntu/dapper-updates/vlc 2 Mature 2009-07-14 12:14:34 UTC
16. * SECURITY UPDATE: (LP: #207284) + d...

Author: Emanuele Gentili
Revision Date: 2008-04-01 03:48:00 UTC

* SECURITY UPDATE: (LP: #207284)
 + debian/patches/031_CVE-2008-1489.dpatch
  - Integer overflow in the MP4_ReadBox_rdrf function in libmp4.c allows
    remote attackers to cause a denial of service (crash) and possibly
    execute arbitrary code via a crafted MP4 RDRF box that triggers a
    heap-based buffer overflow.

* References
 + http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2008-1489
 + http://trac.videolan.org/vlc/changeset/09572892df7e72c0d4e598c0b5e076cf330d8b0a

lp://qastaging/ubuntu/breezy-backports/vlc 1 Development 2009-07-14 12:13:31 UTC
7. Automated backport upload; no source ...

Author: Ubuntu Archive Auto-Sync
Revision Date: 2005-11-18 17:18:19 UTC

Automated backport upload; no source changes.

154 of 54 results