<?xml version="1.0" encoding="utf-8"?><?xml-stylesheet title="XSL formatting" type="text/xsl" href="http://www.jbkempf.com/blog/feed/rss2/xslt" ?><rss version="2.0"
  xmlns:dc="http://purl.org/dc/elements/1.1/"
  xmlns:wfw="http://wellformedweb.org/CommentAPI/"
  xmlns:content="http://purl.org/rss/1.0/modules/content/"
  xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>Yet another blog for JBKempf - Tag - MoAB</title>
  <link>http://www.jbkempf.com/blog/</link>
  <atom:link href="http://www.jbkempf.com/blog/feed/tag/MoAB/rss2" rel="self" type="application/rss+xml"/>
  <description>This is the blog of Jean-Baptiste Kempf. I will share some info about my life, my works and my VideoLAN work</description>
  <language>en</language>
  <pubDate>Mon, 05 Jan 2009 13:17:43 +0100</pubDate>
  <copyright></copyright>
  <docs>http://blogs.law.harvard.edu/tech/rss</docs>
  <generator>Dotclear</generator>
  
    
  <item>
    <title>0.8.6a or how to do a fast release....</title>
    <link>http://www.jbkempf.com/blog/post/2007-0.8.6a-release</link>
    <guid isPermaLink="false">urn:md5:f5eb4482e41d2357a464251f18c276fa</guid>
    <pubDate>Mon, 08 Jan 2007 14:39:00 +0100</pubDate>
    <dc:creator>JBK</dc:creator>
        <category>VideoLAN</category>
        <category>bugs</category><category>MoAB</category><category>Release</category><category>VLC media player</category>    
    <description>&lt;p&gt;This is the short story of how we had to release 0.8.6a version of VLC media player because of some bugs...&lt;/p&gt;    &lt;h4&gt;A Bugfix Release&lt;/h4&gt;

&lt;h3&gt;Intro&lt;/h3&gt;

&lt;p&gt;Everything was going great under the best world. VLC 0.8.6 was out during December without a lot of troubles, with a lot of fixes... A mature release, but...&lt;/p&gt;


&lt;h3&gt;Initial report&lt;/h3&gt;

&lt;p&gt;&lt;a href=&quot;http://applefun.blogspot.com/&quot; hreflang=&quot;en&quot;&gt;Month of Apple Bugs &lt;/a&gt; has started on the first of January. And the second day was a VLC security problem.&lt;/p&gt;


&lt;p&gt;First, we did not think that we could be targeted, because we are not an Apple company... On the same day, there was a patch on the mailing-list. The &lt;strong&gt;fix&lt;/strong&gt; was quite quick in the trunk.&lt;/p&gt;


&lt;h3&gt;Decisions&lt;/h3&gt;

&lt;p&gt;There was a lot of FUD and publicity around that MoAB, so we couldn't do nothing. The problem is that the chief releaser of 0.8.6, and one of the main OSX Coder was away.&lt;/p&gt;


&lt;p&gt;So we decided to release a bugfix version without his advice.&lt;/p&gt;


&lt;p&gt;On the third of January the packages were uploaded, a fix for ancient release was proposed.&lt;/p&gt;


&lt;h3&gt;Release&lt;/h3&gt;

&lt;p&gt;On the 4th, we announced the release after having signed the binaries...&lt;/p&gt;


&lt;h3&gt;The problem&lt;/h3&gt;

&lt;p&gt;&lt;q&gt;VLC media player CDDA (CD Digital Audio) and VCDX (Video CD) plugins are prone to a C-style format string vulnerability when trying to open a media resource location. The bug occurs when handling error and debug messages from underlying library libcdio.&lt;/q&gt;&lt;/p&gt;


&lt;h3&gt;Personal remark&lt;/h3&gt;

&lt;p&gt;A lot of publicity around a non-event. VLC must have a lot of other security problems. We need to analyze a bit more some code...&lt;/p&gt;


&lt;p&gt;But we react quickly enough. &lt;strong&gt;Great!&lt;/strong&gt;&lt;/p&gt;</description>
    
    
    
          <comments>http://www.jbkempf.com/blog/post/2007-0.8.6a-release#comment-form</comments>
      <wfw:comment>http://www.jbkempf.com/blog/post/2007-0.8.6a-release#comment-form</wfw:comment>
      <wfw:commentRss>http://www.jbkempf.com/blog/feed/atom/comments/15</wfw:commentRss>
      </item>
    
</channel>
</rss>