Bug 965227 (CVE-2015-5949) - VUL-0: CVE-2015-5949: vlc: security bug
Summary: VUL-0: CVE-2015-5949: vlc: security bug
Status: RESOLVED FIXED
Alias: CVE-2015-5949
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other openSUSE 13.2
: P5 - None : Major
Target Milestone: ---
Assignee: Dominique Leuenberger
QA Contact: Security Team bot
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2016-02-04 21:56 UTC by Forgotten User KC1n9RYKSj
Modified: 2016-08-05 07:00 UTC (History)
2 users (show)

See Also:
Found By: ---
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments
debian patch (1013 bytes, patch)
2016-02-04 21:56 UTC, Forgotten User KC1n9RYKSj
Details | Diff

Note You need to log in before you can comment on or make changes to this bug.
Description Forgotten User KC1n9RYKSj 2016-02-04 21:56:45 UTC
Created attachment 664513 [details]
debian patch

Dear mantainer, dear developer, 

If I don't miss anything (I'm not very technical person), the package vlc in stable opensuse 13.2 and leap 42.1 is affected by bug CVE-2015-5949.

here 

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-5949

you can find more detailed information.

Both debian and mageia backported upstream patch.

In the alleged file (I hope it could help) I'am attaching debian patch (upstream patch is here

https://git.videolan.org/?p=vlc/vlc-2.2.git;a=commitdiff;h=ce91452460a75d7424b165c4dc8db98114c3cbd9;hp=9e12195d3e4316278af1fa4bcb6a705ff27456fd

).

Thank for you work
kind regards
Tiziano
Comment 1 Bernhard Wiedemann 2016-02-05 10:00:16 UTC
This is an autogenerated message for OBS integration:
This bug (965227) was mentioned in
https://build.opensuse.org/request/show/357850 Factory / vlc
Comment 2 Andreas Stieger 2016-02-05 20:01:32 UTC
Got https://build.opensuse.org/request/show/357853 for 42.1. Does this issue affect openSUSE 13.2 as well?
Comment 3 Dominique Leuenberger 2016-02-05 21:23:50 UTC
(In reply to Andreas Stieger from comment #2)
> Got https://build.opensuse.org/request/show/357853 for 42.1. Does this issue
> affect openSUSE 13.2 as well?

I'm trying to get this information - the patch at least does not apply on 13.2; but that does not mean it's not affected
Comment 4 Dominique Leuenberger 2016-02-05 21:43:02 UTC
(In reply to Dominique Leuenberger from comment #3)
> (In reply to Andreas Stieger from comment #2)
> > Got https://build.opensuse.org/request/show/357853 for 42.1. Does this issue
> > affect openSUSE 13.2 as well?
> 
> I'm trying to get this information - the patch at least does not apply on
> 13.2; but that does not mean it's not affected

ok - 2.1.x tree is also affected - and I got a branch currently building, where I
* Updated vlc to version 2.1.6 (there are quite some other fixes
* Apply the patch for this very issue. Patch applies on this version.

Once I get a build I can do some basic testing.
Comment 5 Andreas Stieger 2016-02-16 16:40:28 UTC
(In reply to Dominique Leuenberger from comment #4)
> (In reply to Dominique Leuenberger from comment #3)
> > (In reply to Andreas Stieger from comment #2)
> > > Got https://build.opensuse.org/request/show/357853 for 42.1. Does this issue
> > > affect openSUSE 13.2 as well?
> > 
> > I'm trying to get this information - the patch at least does not apply on
> > 13.2; but that does not mean it's not affected
> 
> ok - 2.1.x tree is also affected - and I got a branch currently building,
> where I
> * Updated vlc to version 2.1.6 (there are quite some other fixes
> * Apply the patch for this very issue. Patch applies on this version.
> 
> Once I get a build I can do some basic testing.

Ping 13.2?
Comment 6 Swamp Workflow Management 2016-02-16 20:12:07 UTC
openSUSE-SU-2016:0476-1: An update that fixes one vulnerability is now available.

Category: security (important)
Bug References: 965227
CVE References: CVE-2015-5949
Sources used:
openSUSE Leap 42.1 (src):    vlc-2.2.1-24.1
Comment 7 Forgotten User KC1n9RYKSj 2016-02-17 09:24:40 UTC
thanks to all the developers and maintainers involved for their work.

best regards
Tiziano
Comment 8 Dominique Leuenberger 2016-08-05 07:00:28 UTC
VLC 2.1.6 supposedly brought the fix for this too to 13.2 - together with quite some other fixes