LWN.net Logo

Fedora alert FEDORA-2008-7572 (xine-lib)

From:  updates@fedoraproject.org
To:  fedora-package-announce@redhat.com
Subject:  [SECURITY] Fedora 8 Update: xine-lib-1.1.15-1.fc8
Date:  Wed, 10 Sep 2008 06:45:50 +0000
Message-ID:  <20080910064550.6643F2D0043@bastion.fedora.phx.redhat.com>

-------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2008-7572 2008-09-05 10:52:57 -------------------------------------------------------------------------------- Name : xine-lib Product : Fedora 8 Version : 1.1.15 Release : 1.fc8 URL : http://xinehq.de/ Summary : Xine library Description : This package contains the Xine library. Xine is a free multimedia player. It can play back various media. It also decodes multimedia files from local disk drives, and displays multimedia streamed over the Internet. It interprets many of the most common multimedia formats available - and some of the most uncommon formats, too. --with/--without rpmbuild options (some default values depend on target distribution): aalib, caca, directfb, imagemagick, freetype, antialiasing (with freetype), pulseaudio, xcb. -------------------------------------------------------------------------------- Update Information: This release fixes multiple bugs and security issues: - DoS via corrupted Ogg files (CVE-2008-3231) - multiple possible buffer overflows detailed in oCERT-2008-008 For more details, see: http://sourceforge.net/project/shownotes.php?release_id=6... http://www.ocert.org/advisories/ocert-2008-008.html NOTE: A coordinated release with 3rd-party repos was not possible, so this update may result in dependency issues with currently-installed xine-lib-extras-* rpms. This temporary problem will be rectified asap. -------------------------------------------------------------------------------- ChangeLog: * Wed Aug 20 2008 Rex Dieter <rdieter@fedoraproject.org> - 1.1.15-1 - xine-lib-1.1.15, plugin ABI 1.24 (rh#455752, CVE-2008-3231) - Obsoletes: -arts (f9+) * Sun Apr 27 2008 Kevin Kofler <Kevin@tigcc.ticalc.org> - 1.1.12-3 - rebuild for new ImageMagick (6.4.0.10) * Thu Apr 24 2008 Rex Dieter <rdieter@fedoraproject.org> - 1.1.12-2 - CVE-2008-1878 * Wed Apr 16 2008 Ville Skyttä <ville.skytta at iki.fi> - 1.1.12-1 - 1.1.12 (plugin ABI 1.21); qt, mkv, and pulseaudio patches applied upstream. * Wed Apr 9 2008 Ville Skyttä <ville.skytta at iki.fi> - 1.1.11.1-3 - Apply upstream fixes for Quicktime (#441705) and Matroska regressions introduced in 1.1.11.1. * Mon Apr 7 2008 Rex Dieter <rdieter@fedoraproject.org> - 1.1.11.1-2 - pulse-rework2 patch (#439731) - -pulseaudio subpkg (#439731) * Sun Mar 30 2008 Ville Skyttä <ville.skytta at iki.fi> - 1.1.11.1-1 - 1.1.11.1 (security update, #438663, CVE-2008-1482). - Provide versioned xine-lib(plugin-abi) so 3rd party packages installing plugins can use it instead of requiring a version of xine-lib. * Wed Mar 19 2008 Ville Skyttä <ville.skytta at iki.fi> - 1.1.11-1 - 1.1.11 (security update, #438182, CVE-2008-0073). - Drop jack and wavpack build conditionals. - Specfile cleanups. * Fri Mar 7 2008 Rex Dieter <rdieter@fedoraproject.org> - 1.1.10.1-1.1 - xcb support for f7+ (#373411) * Fri Feb 8 2008 Ville Skyttä <ville.skytta at iki.fi> - 1.1.10.1-1 - 1.1.10.1 (security update, #431541). * Sun Jan 27 2008 Ville Skyttä <ville.skytta at iki.fi> - 1.1.10-2 - Include spu, spucc, and spucmml decoders (#213597). * Sun Jan 27 2008 Ville Skyttä <ville.skytta at iki.fi> - 1.1.10-1 - 1.1.10 (security update). * Mon Jan 21 2008 Ville Skyttä <ville.skytta at iki.fi> - 1.1.9.1-3 - Fix version number in libxine.pc (#429487). * Sun Jan 20 2008 Ville Skyttä <ville.skytta at iki.fi> - 1.1.9.1-2 - Disable upstream "discard buffers on ao close" 1.1.9 changeset (#429182). * Sat Jan 12 2008 Ville Skyttä <ville.skytta at iki.fi> - 1.1.9.1-1 - 1.1.9.1 (security update). * Sun Jan 6 2008 Ville Skyttä <ville.skytta at iki.fi> - 1.1.9-1 - 1.1.9. * Thu Sep 27 2007 Ville Skyttä <ville.skytta at iki.fi> - 1.1.8-6 - Enable wavpack support by default for all distros. * Sun Sep 23 2007 Ville Skyttä <ville.skytta at iki.fi> - 1.1.8-5 - Enable JACK support by default for all distros. -------------------------------------------------------------------------------- References: [ 1 ] Bug #456057 - CVE-2008-3231 xine-lib: crash on zzuf test case lol-ffplay.ogg https://bugzilla.redhat.com/show_bug.cgi?id=456057 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update xine-lib' at the command line. For more information, refer to "Managing Software with yum", available at http://docs.fedoraproject.org/yum/. All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at http://fedoraproject.org/keys -------------------------------------------------------------------------------- _______________________________________________ Fedora-package-announce mailing list Fedora-package-announce@redhat.com http://www.redhat.com/mailman/listinfo/fedora-package-ann...


(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds