Bug#502314: vlc: CVE-2008-4558 code execution via crafted xspf playlist file

2008-10-15 Thread Nico Golde
Hi, forgot the patch. http://git.videolan.org/?p=vlc.git;a=commit;h=6d3c22f29e650b0d10b2116fe3145194d20b8b56 -- Nico Golde - http://www.ngolde.de - [EMAIL PROTECTED] - GPG: 0x73647CFF For security reasons, all text in this mail is double-rot13 encrypted. pgpjgOsRTm7AG.pgp Description: PGP sign

Bug#502314: vlc: CVE-2008-4558 code execution via crafted xspf playlist file

2008-10-15 Thread Nico Golde
Package: vlc Severity: grave Tags: security patch Hi, the following CVE (Common Vulnerabilities & Exposures) id was published for vlc. CVE-2008-4558[0]: | Array index error in VLC media player 0.9.2 allows remote attackers to | overwrite arbitrary memory and execute arbitrary code via an XSPF | p