I am loosing more and more confidence that these "package the world and freeze everything in place" distros are the right choice for end users.
About the “Security Issue” on VLC
21–30 of 174 posts
Re: About the “Security Issue” on VLC
#22Earlier quoted context omitted.
> I really wonder where the CVE got their "attack vector: network" and CERT "remote: yes" classifications from. They always do that with VLC: even file can be on a playlist, and a playlist can be sent by email or over the web, with a link... So they classify all VLC bugs with network and remote.
By that token, is there ANY application where the attack vector is not 'network' and 'remote' is 'no'? Because I fail to think of any minimally-useful app that doesn't open external files.
Re: About the “Security Issue” on VLC
#23I don't like the exchange with TheRegister: > TheRegister: FWIW we reported the VLC developers were skeptical. Happy to update our coverage accordingly. > Tho, FWIW, the PoC .MP4 seg-faulted our 3.0.7 VLC installation. > VideoLAN: using a linux distribution? with an old libebml? > TheRegister: Using Debian 9.9, using libebml4v5 1.3.4-1 > VideoLAN: Yes, so your issue is your distribution is not up-to-date, not VLC. No…
Especially, since the very very large majority of VLC users are not on Linux, but using binaries.
Re: About the “Security Issue” on VLC
#24Re: About the “Security Issue” on VLC
#25> The reporter is using Ubuntu 18.04, which is an old version of Ubuntu, and clearly has not all the updated libraries. It's not a "old" version of Ubuntu its the latest LTS.
That's the point of LTS.
Re: About the “Security Issue” on VLC
#26I think the VLC developers come off as pretty defensive in this. They flame the reporter for opening the issue on the issue tracker, but on the issue the reporter says that he got no response from the VLC security contact which he tried first. Then, they dismiss the vulnerability and flame the CVE assigners, because VLC themselves are shipping a distribution with the vuln fixed, even though many Linux distributions a…
- the reporter never contacted us, we have a clear process and a bounty program. We checked again, he never did.
- we receive and process all security issues privately: we fixed 31 of them in the last update. And miracly, the other reporters managed to contact us.
- Linux is the smallest OS for VLC.
- An issue on one or two Linux distribution for a OOB-read crash is very very different from "VLC vulnerable on all machines, uninstall now!"
- The CVE number of 9.8 makes no sense. How do you even exploit this crash?
- VLC has DEP and ASLR activated everywhere. How do you execute code with this read issue?
Re: About the “Security Issue” on VLC
#27> The reporter is using Ubuntu 18.04, which is an old version of Ubuntu, and clearly has not all the updated libraries. It's not a "old" version of Ubuntu its the latest LTS.
Alternatively (because libebml is "universe", that is, unsupported), stop ripping out maintained components from projects to "use system packages instead" which are not maintained.
It's stuff like this that makes Firefox and Pale Moon play hardball with distros that mess up their software. (nevermind that the Pale Moon devs aren't even trying to solve such things amicably)
Re: About the “Security Issue” on VLC
#28I think the VLC developers come off as pretty defensive in this. They flame the reporter for opening the issue on the issue tracker, but on the issue the reporter says that he got no response from the VLC security contact which he tried first. Then, they dismiss the vulnerability and flame the CVE assigners, because VLC themselves are shipping a distribution with the vuln fixed, even though many Linux distributions a…
Absolutely not: - the reporter never contacted us, we have a clear process and a bounty program. We checked again, he never did. - we receive and process all security issues privately: we fixed 31 of them in the last update. And miracly, the other reporters managed to contact us. - Linux is the smallest OS for VLC. - An issue on one or two Linux distribution for a OOB-read crash is very very different from "VLC vulne…
Re: About the “Security Issue” on VLC
#29Earlier quoted context omitted.
But the biggest issue is that they refuse that we become the CNA for VLC bugs. So, they are the root CNA for VLC bugs, and they don't triage them correctly. And don't update the issues when we mention them.
Why can't you be an authority of your CVEs without consulting an American gov agency? I'm sure, VLC org is way more trustworthy for nine out of ten people on the Earth.
Re: About the “Security Issue” on VLC
#30So none of the tech news websites contacted VideoLAN and published their articles without checking their source. I believe this sums up the problem with online news: being first matters most to news sites. It drives traffic. Accurate reporting comes second. I feel bad for VideoLAN, according to them the bug was in a 3rd party lib and was fixed 16 months ago.
VLC is not a commercial product, but equally still took the same impact from this and as we know, many end-user will be oblivious of any retraction as the case with many media retractions/corrections that get buried and do not traction.
Maybe we need Open Lawyer as well as Open Source!
I'm of the thinking that the only way media would get any education would be litigation. Sad I know, but that is the World they operate in. Why else do media outlets have lawyer departments.