1 February 2011|10 years of open source for VideoLAN|The VideoLAN project and organization are proud to celebrate with the community the <b>10<sup>th</sup> anniversary</b> of open sourcing of all VideoLAN software, that happened exactly 10 years ago.</p><p>To celebrate, small infos, stories and goodies will be posted in the next ten days on <a href="/videolan/events/10y/">this site</a>.<br /><a href="/videolan/events/10y/">Day 1</a> speaks about the <a href="/videolan/events/10y/">early history of the project</a><br />Please <b>join</b> the celebration!
|23 January 2011|VLC 1.1.6|VideoLAN and the VLC development team are proud to present VLC 1.1.6, the sixth bugfix release of the VLC 1.1.x branch.<br />Small new features, many bugfixes, updated translations and <a href="/security/sa1007.html">security issues</a> are making this release. Notable improvements include codecs, demuxers, Audio-CD support, subtitles, visualization and platform integration.<br />Source and Windows and MacOSX builds are available.<br />See the <a href="/vlc/releases/1.1.6.html">release notes</a> for more information.<br />
<b>NB:</b> The first versions for Intel-based Macs (64bit and Universal Binary) included a rtsp streaming bug, which also hindered access to the Freebox. Please re-download.
......@@ -28,6 +28,11 @@ pub 1024D/AC3E0879 2006-03-01
<dt>VideoLAN-SA-1102 (?)</dt>
<dd>Insufficient input validation in MKV demuxer.
<a href="sa1102.html">Details</a>
<dt>VideoLAN-SA-1101 (CVE-2011-0021)</dt>
<dd>Heap corruption in CDG codec.
<a href="sa1101.html">Details</a>
<dt>Dan Rosenberg, VSR</dt>
<dd><a href=""
<h1>Security Advisory 1102</h1>
Summary : Insufficient input validation in MKV demuxer
Date : January 2011
Affected versions : VLC media player and earlier
ID : VideoLAN-SA-1102
CVE reference : Unassigned
<p>When parsing an invalid MKV (Matroska or WebM) file,
input validation are insufficient.
<p>If successful,
a malicious third party will be able to trigger execution of arbitrary code.
<h2>Threat mitigation</h2>
<p>Exploitation of this issue requires the user
to explicitly open a specially crafted file.
<p>The user should refrain from opening files from untrusted third parties
or accessing untrusted remote sites (or disable the VLC browser plugins),
until the patch is applied.
<p>Alternatively, the MKV demuxer plugin
can be removed manually from the VLC plugin installation directory.
<p>VLC media player 1.1.7 addresses this issue.
Patches for older versions are available
from the official VLC source code repositories.
<p>This vulnerability was reported by Dan Rosenberg from VSR.
<dt>The VideoLAN project</dt>
<dd><a href=""></a>
<dt>VLC official GIT repository</dt>
<dd><a href=";a=commit;h=59491dcedffbf97612d2c572943b56ee4289dd07">;a=commit;h=59491dcedffbf97612d2c572943b56ee4289dd07</a>
<dt>Dan Rosenberg, VSR</dt>
<dd><a href=""
<dt>26 January 2011</dt>
<dd>Vendor notified</dd>
<dt>29 January 2011</dt>
<dd>Fixes delivered by Matroska</dd>
<dt>30 January 2011</dt>
<dd>Patches published</dd>
<dd>Security advisory published</dd>
<dd>VLC media player 1.1.7 released</dd>
<dd>CVE ID reserved</dd>
<address>R&eacute;mi Denis-Courmont,<br />
on behalf of the VideoLAN project</address>
<h1>10 years of Open Source</h1>
<h2>Welcome to the pages for the Celebration of our 10 years of open source</h2>
<p>We are here to celebrate the 10 years of the open sourcing of VideoLAN and VLC.</p>
<p><b>10 days</b> of surprises, ideas and stories will pop up here.</p>
<br />
<br />
<div id="left">
<h1>Day 1: a VideoLAN history</h1>
<p>Most people know <a href="/vlc"/>VLC</a>, but they don't know the history of the <a href="/videolan/">VideoLAN project</a>.</p>
<p>Well, they don't even know what VideoLAN is, and that we are not a company...</p>
<h2>1st February 2011</h2>
<p>Today is the <b>10<sup>th</sup> anniversary</b> of the switch to <a href="">GPL</a> of the VideoLAN project
<p>But, but, but... What was <em>before</em> the GPL?</p>
<h3>1996: First VideoLAN project</h3>
<p>The network of the campus of the <a href="">École Centrale Paris</a>,
one of the prestigious French "<a href="">Grande École</a>"
university, has always been managed by a student organisation named <a href="">
VIA Centrale Réseaux</a>.</p>
<p>In 1996, it had a very slow <a href="">Token-Ring</a> network, but the students wanted an upgrade. They found investors
at the condition that they could justify the need for a new network...</p>
<p>Therefore, they decided to push <b>Video</b> on the network...<br />
<p>Remember, this is <b>1996</b>, were your average Pentium couldn't decode a DVD and when Youtube and Google didn't exist...</p>
<p>This <b>student project</b> achieved his goals in early 1998, and a new network came.</p>
<h3>1998: Second VideoLAN project</h3>
<p>As it was successful, it was decided to go on the project.</p>
<p>And they restarted the project from scratch, in <b>1998</b>.<br />
<p>But in the mind of <a href="">open source</a> and modularity.</p>
<p>This is when the <a href="/vlc/">VLC media player</a> that you know of, was <i>born</i>.<br />
If you look at the <em>first commit</em> of the repository, in <b>August 1999</b>, you'll see that the most copyright
indeed is from <b>1998</b>.</p>
<h3>2001: Open Source</h3>
<p>As <a href="/">VideoLAN</a> was a student project, the university had moral rights on the software produced.</p>
<p>Thanks to the <b>students</b> and Professor <a href="">Jean-Philippe Rey</a>,
the direction of the university allowed the switch of all code produced to GPL.</p>
<p>The <a href="">letter</a> from Mr. Gourisse was signed on February 1<sup>st</sup>, <b>2001</b>.</p>
<h2>Since 2001</h2>
<p>Afterward, the project has went on, with <b>students</b> and then <b>volunteers</b> from around the world.</p>
<p>The project, has, of course, left the university and is a backed-up by a <b>volunteer non-profit organisation</b>.</p>
<p>Today, VLC averages 24 million downloads per month (including two-third of updates) and the user-base is counted in tens of million.</p>
<h2>Support us</h2>
<p>Since all the work on <a href="/vlc/">VLC</a> and other <a href="/projects">videolan projects</a> is done by <b>volunteers</b>
in their <b>free time</b>, we welcome donations to help us manage the software.</p>
<p><b>Donate <a href="/contribute.html">now!</a></b></p>
<div id="right">
<h1><a href="/videolan/events/10y/">Day 1</a></h1>
