{"id":"MGASA-2016-0221","summary":"Updated vlc/mad packages fix security vulnerability","details":"A vulnerability was found in processing QuickTime IMA files. VLC does not\ncheck that the number of channels in the input stream is less than or\nequal to the size of the buffer, resulting in an out-of-bounds write\npotential for remote code execution via a malicious media file\n(CVE-2016-5108).\n\nThe vlc package has been updated to version 2.2.4, which fixes this issue\nand other bugs.\n\nAlso, the mad package has been patched to fix an out-of-bounds write which\ncould cause VLC or other applications linked to that library to crash on\nan invalid mp3 file.\n","modified":"2026-04-16T06:23:10.661025484Z","published":"2016-06-10T19:06:07Z","upstream":["CVE-2016-5108"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2016-0221.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=18567"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2016/05/27/7"},{"type":"WEB","url":"http://git.videolan.org/?p=vlc/vlc-2.2.git;a=blob;f=NEWS;h=1af86bef0317c8882acc363a7c8fc5e83097c7bd;hb=888b7e89d78e7073075fc0a007d47b93f4570fab"}],"affected":[{"package":{"name":"mad","ecosystem":"Mageia:5","purl":"pkg:rpm/mageia/mad?arch=source&distro=mageia-5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.15.1b-16.1.mga5"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2016-0221.json"}},{"package":{"name":"vlc","ecosystem":"Mageia:5","purl":"pkg:rpm/mageia/vlc?arch=source&distro=mageia-5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.2.4-1.mga5"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2016-0221.json"}},{"package":{"name":"vlc","ecosystem":"Mageia:5","purl":"pkg:rpm/mageia/vlc?arch=source&distro=mageia-5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.2.4-1.mga5.tainted"}]}],"ecosystem_specific":{"section":"tainted"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2016-0221.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}