Live data from Hacker News

About the “Security Issue” on VLC

twitter.com

21–30 of 174 posts

Re: About the “Security Issue” on VLC

#21
libebml is in the Ubuntu universe repository which means that it is not supported by Canonical. And in the Debian changelog for this package I don't see any mentions of a security issue that was fixed 16 months ago: https://metadata.ftp-master.debian.org/changelogs//main/libe...

I am loosing more and more confidence that these "package the world and freeze everything in place" distros are the right choice for end users.

Re: About the “Security Issue” on VLC

#22
post #17
post #14

Earlier quoted context omitted.

> I really wonder where the CVE got their "attack vector: network" and CERT "remote: yes" classifications from. They always do that with VLC: even file can be on a playlist, and a playlist can be sent by email or over the web, with a link... So they classify all VLC bugs with network and remote.

By that token, is there ANY application where the attack vector is not 'network' and 'remote' is 'no'? Because I fail to think of any minimally-useful app that doesn't open external files.

Because we support playlists. I know it does make sense, but Mitre is never answering.

Re: About the “Security Issue” on VLC

#23
post #20

I don't like the exchange with TheRegister: > TheRegister: FWIW we reported the VLC developers were skeptical. Happy to update our coverage accordingly. > Tho, FWIW, the PoC .MP4 seg-faulted our 3.0.7 VLC installation. > VideoLAN: using a linux distribution? with an old libebml? > TheRegister: Using Debian 9.9, using libebml4v5 1.3.4-1 > VideoLAN: Yes, so your issue is your distribution is not up-to-date, not VLC. No…

An issue on one or two Linux distribution for a OOB-read crash is very very different from "VLC vulnerable on all machines, uninstall now!"

Especially, since the very very large majority of VLC users are not on Linux, but using binaries.

Re: About the “Security Issue” on VLC

#24
I think the VLC developers come off as pretty defensive in this. They flame the reporter for opening the issue on the issue tracker, but on the issue the reporter says that he got no response from the VLC security contact which he tried first. Then, they dismiss the vulnerability and flame the CVE assigners, because VLC themselves are shipping a distribution with the vuln fixed, even though many Linux distributions and presumably other distributors of VLC remain vunerable - a situation clearly requireing vulnerability coordination and a CVE assignment.

Re: About the “Security Issue” on VLC

#26
post #24

I think the VLC developers come off as pretty defensive in this. They flame the reporter for opening the issue on the issue tracker, but on the issue the reporter says that he got no response from the VLC security contact which he tried first. Then, they dismiss the vulnerability and flame the CVE assigners, because VLC themselves are shipping a distribution with the vuln fixed, even though many Linux distributions a…

Absolutely not:

- the reporter never contacted us, we have a clear process and a bounty program. We checked again, he never did.

- we receive and process all security issues privately: we fixed 31 of them in the last update. And miracly, the other reporters managed to contact us.

- Linux is the smallest OS for VLC.

- An issue on one or two Linux distribution for a OOB-read crash is very very different from "VLC vulnerable on all machines, uninstall now!"

- The CVE number of 9.8 makes no sense. How do you even exploit this crash?

- VLC has DEP and ASLR activated everywhere. How do you execute code with this read issue?

Re: About the “Security Issue” on VLC

#27

> The reporter is using Ubuntu 18.04, which is an old version of Ubuntu, and clearly has not all the updated libraries. It's not a "old" version of Ubuntu its the latest LTS.

Just that Ubuntu apparently forgot about the "S" part of "LTS", or they could have updated that package.

Alternatively (because libebml is "universe", that is, unsupported), stop ripping out maintained components from projects to "use system packages instead" which are not maintained.

It's stuff like this that makes Firefox and Pale Moon play hardball with distros that mess up their software. (nevermind that the Pale Moon devs aren't even trying to solve such things amicably)

Re: About the “Security Issue” on VLC

#28
post #26
post #24

I think the VLC developers come off as pretty defensive in this. They flame the reporter for opening the issue on the issue tracker, but on the issue the reporter says that he got no response from the VLC security contact which he tried first. Then, they dismiss the vulnerability and flame the CVE assigners, because VLC themselves are shipping a distribution with the vuln fixed, even though many Linux distributions a…

Absolutely not: - the reporter never contacted us, we have a clear process and a bounty program. We checked again, he never did. - we receive and process all security issues privately: we fixed 31 of them in the last update. And miracly, the other reporters managed to contact us. - Linux is the smallest OS for VLC. - An issue on one or two Linux distribution for a OOB-read crash is very very different from "VLC vulne…

Since this is tarnishing your brand, maybe ask Ubuntu to cease shipping "VLC" if they do such a half-assed job (enough effort to replace integrated libraries with system packages, not enough effort to maintain those packages)?

Re: About the “Security Issue” on VLC

#29
post #13

Earlier quoted context omitted.

But the biggest issue is that they refuse that we become the CNA for VLC bugs. So, they are the root CNA for VLC bugs, and they don't triage them correctly. And don't update the issues when we mention them.

Why can't you be an authority of your CVEs without consulting an American gov agency? I'm sure, VLC org is way more trustworthy for nine out of ten people on the Earth.

Because everyone uses CVE. And then, it gets in the press...

Re: About the “Security Issue” on VLC

#30
post #2

So none of the tech news websites contacted VideoLAN and published their articles without checking their source. I believe this sums up the problem with online news: being first matters most to news sites. It drives traffic. Accurate reporting comes second. I feel bad for VideoLAN, according to them the bug was in a 3rd party lib and was fixed 16 months ago.

If VLC was a commercial product, this would be a lawyer time for effectively damaging reputation based upon lies and would see many media outlet dragged over the coals.

VLC is not a commercial product, but equally still took the same impact from this and as we know, many end-user will be oblivious of any retraction as the case with many media retractions/corrections that get buried and do not traction.

Maybe we need Open Lawyer as well as Open Source!

I'm of the thinking that the only way media would get any education would be litigation. Sad I know, but that is the World they operate in. Why else do media outlets have lawyer departments.

Post reply on HN