[Bug 1693893] Re: Possible remote code execution related to subtitles

2017-07-09 Thread Simon Quigley
Urgh, I attached a completely unrelated file from another directory... apologies, here's the ACTUAL file applicable to 2.2.2-5ubuntu0.16.04.2. ** Patch added: "1-2.2.2-5ubuntu0.16.04.3.debdiff" https://bugs.launchpad.net/ubuntu/+source/vlc/+bug/1693893/+attachment/4911982/+files/1-2.2.2-5ubunt

[Bug 1693893] Re: Possible remote code execution related to subtitles

2017-07-09 Thread Simon Quigley
Here's a patch applicable to version 2.2.2-5ubuntu0.16.04.2 in Xenial. I have built it with no problems in ppa:tsimonq2/vlc-bug-1693893 and I have tested it on a fully updated Lubuntu 16.04.2 installation (it works completely fine). ** Patch added: "2.2.12-10ubuntu1.patch" https://bugs.launchp

[Bug 1693893] Re: Possible remote code execution related to subtitles

2017-07-07 Thread Simon Quigley
** CVE added: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2017-8310 -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1693893 Title: Possible remote code execution related to subtitles To manage not

[Bug 1693893] Re: Possible remote code execution related to subtitles

2017-07-07 Thread Marc Deslauriers
** Also affects: vlc (Ubuntu Artful) Importance: Undecided Assignee: Simon Quigley (tsimonq2) Status: In Progress -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1693893 Title: Possible

[Bug 1693893] Re: Possible remote code execution related to subtitles

2017-07-07 Thread Simon Quigley
** Changed in: vlc (Ubuntu Xenial) Assignee: (unassigned) => Simon Quigley (tsimonq2) ** Changed in: vlc (Ubuntu Zesty) Assignee: (unassigned) => Simon Quigley (tsimonq2) ** Changed in: vlc (Ubuntu Xenial) Status: New => In Progress ** Changed in: vlc (Ubuntu Zesty) Statu

[Bug 1693893] Re: Possible remote code execution related to subtitles

2017-07-07 Thread Simon Quigley
** CVE added: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2017-10699 -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1693893 Title: Possible remote code execution related to subtitles To manage no

[Bug 1693893] Re: Possible remote code execution related to subtitles

2017-07-07 Thread Marc Deslauriers
** Also affects: vlc (Ubuntu Zesty) Importance: Undecided Status: New ** Also affects: vlc (Ubuntu Xenial) Importance: Undecided Status: New -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.ne

[Bug 1693893] Re: Possible remote code execution related to subtitles

2017-07-07 Thread Simon Quigley
** Changed in: vlc (Ubuntu) Status: Incomplete => In Progress ** Changed in: vlc (Ubuntu) Assignee: (unassigned) => Simon Quigley (tsimonq2) ** CVE added: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2016-5108 -- You received this bug notification because you are a member of Ubunt

[Bug 1693893] Re: Possible remote code execution related to subtitles

2017-07-07 Thread Simon Quigley
** CVE removed: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2017-8310 -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1693893 Title: Possible remote code execution related to subtitles To manage n

[Bug 1693893] Re: Possible remote code execution related to subtitles

2017-05-26 Thread pcworld
** CVE added: http://www.cve.mitre.org/cgi- bin/cvename.cgi?name=2017-8310 ** CVE added: http://www.cve.mitre.org/cgi- bin/cvename.cgi?name=2017-8311 ** CVE added: http://www.cve.mitre.org/cgi- bin/cvename.cgi?name=2017-8312 ** CVE added: http://www.cve.mitre.org/cgi- bin/cvename.cgi?name=2017-8

[Bug 1693893] Re: Possible remote code execution related to subtitles

2017-05-26 Thread Seth Arnold
Hello pcworld, if you have the time to tackle this update please do note that there may be other issues still open: http://people.canonical.com/~ubuntu-security/cve/pkg/vlc.html Thanks -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu.

[Bug 1693893] Re: Possible remote code execution related to subtitles

2017-05-26 Thread Seth Arnold
Thanks for taking the time to report this bug and helping to make Ubuntu better. Since the package referred to in this bug is in universe or multiverse, it is community maintained. If you are able, I suggest coordinating with upstream and posting a debdiff for this issue. When a debdiff is availabl