Bug 973354 (CVE-2016-3941) - VUL-0: CVE-2016-3941: vlc: Heap overflow in processing wav files
Summary: VUL-0: CVE-2016-3941: vlc: Heap overflow in processing wav files
Status: RESOLVED FIXED
Alias: CVE-2016-3941
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other openSUSE 42.1
: P3 - Medium : Normal
Target Milestone: ---
Assignee: Dominique Leuenberger
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/165270/
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2016-03-31 08:58 UTC by Johannes Segitz
Modified: 2016-08-05 06:57 UTC (History)
1 user (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Johannes Segitz 2016-03-31 08:58:34 UTC
CVE-2016-3941

Reproducer and details in
https://bugs.launchpad.net/ubuntu/+source/vlc/+bug/1533633
According to that the current git snapshot doesn't crash on the reproducer.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2016-3941
http://seclists.org/oss-sec/2016/q1/722
Comment 1 Dominique Leuenberger 2016-03-31 09:16:25 UTC
Tests done:

Tumbleweed (vlc 2.2.2): No crash
Leap 42.1  (vlc 2.2.1): No crash

Still need to test 13.2 (vlc 2.1.5): likely affected, as CVE-2016-3941 references 2.1.6
Comment 2 Swamp Workflow Management 2016-03-31 22:01:02 UTC
bugbot adjusting priority
Comment 3 Dominique Leuenberger 2016-06-13 20:28:11 UTC
Submitted for 13.2 Leap and TW seem unaffected
Comment 4 Swamp Workflow Management 2016-06-22 12:09:58 UTC
openSUSE-SU-2016:1651-1: An update that fixes two vulnerabilities is now available.

Category: security (important)
Bug References: 973354,984382
CVE References: CVE-2016-3941,CVE-2016-5108
Sources used:
openSUSE 13.2 (src):    vlc-2.1.6-2.10.1
Comment 5 Dominique Leuenberger 2016-08-05 06:57:33 UTC
For 13.2 we released an update - Leap and TW were not affected to start with