oss-sec mailing list archives

Re: [videolan] [oss-security] older issues in libbluray


From: Jean-Baptiste Kempf <jb () videolan org>
Date: Mon, 23 Feb 2015 16:47:26 +0100

On 23 Feb, Kurt Seifried wrote :
Again my apologies for this mess. The good news is that all our current
embargoed flaws (none against VLC currently =) are being actively
handled (e.g. worked on in a current time frame) and moving forwards we
should hopefully be able to avoid issues like this.

One libbluray issue was already fixed.
The second one is not really fixable, since BD-J is actually executing
java code from the outside.

Also one request (not just specific to VLC, but everyone with a
project): please have a security@ email address for your project or a
security web page that makes it obvious how to contact and report things

We have a security email.

With my kindest regards,

-- 
Jean-Baptiste Kempf
http://www.jbkempf.com/ - +33 672 704 734
Sent from my Electronic Device


Current thread: