Bug#622091: [vlc-devel] Bug#622091: libmodplug ReadS3M stack overflow

2011-04-10 Thread Martin Storsjö
On Sun, 10 Apr 2011, Rémi Denis-Courmont wrote: > Hello, > > Le dimanche 10 avril 2011 18:34:34 Nico Golde, vous avez écrit : > > * Remi Denis-Courmont [2011-04-10 09:36]: > > > An exploitable memory corruption vulnerability has been publicized > > > against libmodplug 0.8.8.1: > > > http:

Bug#622091: libmodplug ReadS3M stack overflow

2011-04-10 Thread Rémi Denis-Courmont
Hello, Le dimanche 10 avril 2011 18:34:34 Nico Golde, vous avez écrit : > * Remi Denis-Courmont [2011-04-10 09:36]: > > An exploitable memory corruption vulnerability has been publicized > > against libmodplug 0.8.8.1: > > http://seclists.org/fulldisclosure/2011/Apr/113 > > > > Upstream

Bug#622091: libmodplug ReadS3M stack overflow

2011-04-10 Thread Nico Golde
Hi, * Remi Denis-Courmont [2011-04-10 09:36]: > An exploitable memory corruption vulnerability has been publicized > against libmodplug 0.8.8.1: > http://seclists.org/fulldisclosure/2011/Apr/113 > > Upstream version 0.8.8.2 fixes the issue. How important is this library for vlc and others from a

Bug#622091: libmodplug ReadS3M stack overflow

2011-04-10 Thread Remi Denis-Courmont
Package: libmodplug Version: 1:0.8.8.1-2 Severity: grave Tags: security upstream Justification: user security hole Hello, An exploitable memory corruption vulnerability has been publicized against libmodplug 0.8.8.1: http://seclists.org/fulldisclosure/2011/Apr/113 Upstream version 0.8.8