Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [day] [month] [year] [list]
Date: Wed, 24 Oct 2012 18:34:40 -0400 (EDT)
From: cve-assign@...re.org
To: oss-security@...ts.openwall.com
Cc: cve-assign@...re.org
Subject: VLC 2.0.3 libpng_plugin CVE-2012-5470

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

We have assigned CVE-2012-5470 for this issue in libpng_plugin in
VideoLAN VLC media player 2.0.3 processing a PNG file:

  http://www.exploit-db.com/exploits/21889/

The "Rewritten support for images, including jpeg, png, xcf, bmp..."
and "2.0.4 fixes numerous issues, including audio device selection, Qt
and Mac OS interface, security issues and Windows wallpaper mode..."
lines in http://www.videolan.org/vlc/releases/2.0.4.html may possibly
be relevant here. There isn't an obvious mention of PNG on the
http://trac.videolan.org/vlc/timeline?from=10%2F24%2F12&daysback=15
ticket list.

- -- 
CVE assignment team, MITRE CVE Numbering Authority
M/S M300
202 Burlington Road, Bedford, MA 01730 USA
[ PGP key available through http://cve.mitre.org/cve/request_id.html ]
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.11 (SunOS)

iQEcBAEBAgAGBQJQiGv9AAoJEGvefgSNfHMd684H/37tnXLm0bQK7/vdVK6Vmk/+
ELm/9/62ijQOkDhQWUxS+ZmhP7L/jA24cieMHrpiTzlFOGrVX+ly3n6/nlpgyzFr
Giq5fCIsIi1UD1eXftMsORmAQr+TjJ9ppV9D31C1HQO9itavnwb43kKVU8yrBZDv
b+UTFX19iXyvNwMino7S3P9ibMxKNnqoP3nxM1Z4IwqOMB6ESp9RzQv0kp8xu5vq
+Rb7vFsWqkdqg0Bs7ct65ehrW+7xRzoFQ/fCEUKeXi7j0jmZxHE46DSjtZNcj/Ox
s9sWxaW/MQ6zc14vEf8R6Ouf/ur/E6zj2uXsF4Ajo2NQIiEntnglht3nsoO94VE=
=eugH
-----END PGP SIGNATURE-----

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.