Processed: Re: Bug#811519: vlc: avio plugin leaks file content

2016-01-19 Thread Debian Bug Tracking System
Processing control commands: > tags -1 = moreinfo Bug #811519 [src:ffmpeg] ffmpeg: needs to build with --disable-protocol=concat to really fix CVE-2016-1897 Added tag(s) moreinfo; removed tag(s) patch and security. > severity -1 important Bug #811519 [src:ffmpeg] ffmpeg: needs to build with --dis

Bug#811519: vlc: avio plugin leaks file content

2016-01-19 Thread Andreas Cadhalpun
Control: tags -1 = moreinfo Control: severity -1 important Hi, On 19.01.2016 17:27, Sebastian Ramacher wrote: > On 2016-01-19 18:11:01, Rémi Denis-Courmont wrote: >> With a carefully crafted URL, the VLC avio plugin can be made to leak >> content of local files to remote parties. >> The root caus

Bug#811519: vlc: avio plugin leaks file content

2016-01-19 Thread Sebastian Ramacher
Control: reassign -1 src:ffmpeg 7:2.8.4-1 Control: retitle -1 ffmpeg: needs to build with --disable-protocol=concat to really fix CVE-2016-1897 On 2016-01-19 18:11:01, Rémi Denis-Courmont wrote: > Package: vlc > Version: 2.2.1-5+b1 > Severity: grave > Tags: security patch > Justification: user se

Processed: Re: Bug#811519: vlc: avio plugin leaks file content

2016-01-19 Thread Debian Bug Tracking System
Processing control commands: > reassign -1 src:ffmpeg 7:2.8.4-1 Bug #811519 [vlc-nox] vlc: avio plugin leaks file content Bug reassigned from package 'vlc-nox' to 'src:ffmpeg'. No longer marked as found in versions vlc/2.2.0~rc2-2+deb8u1. Ignoring request to alter fixed versions of bug #811519 to

Bug#811519: vlc: avio plugin leaks file content

2016-01-19 Thread Rémi Denis-Courmont
Package: vlc Version: 2.2.1-5+b1 Severity: grave Tags: security patch Justification: user security hole Dear Maintainer, With a carefully crafted URL, the VLC avio plugin can be made to leak content of local files to remote parties. The root cause is the same as CVE-2016-1897. See also: https:/