LWN.net Logo

Fedora alert FEDORA-2012-4070 (gnash)

From:  updates@fedoraproject.org
To:  package-announce@lists.fedoraproject.org
Subject:  [SECURITY] Fedora 15 Update: gnash-0.8.10-2.fc15
Date:  Mon, 26 Mar 2012 04:01:22 +0000
Message-ID:  <20120326040122.CF50820D62@bastion01.phx2.fedoraproject.org>
Archive-link:  Article, Thread

-------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2012-4070 2012-03-17 23:00:45 -------------------------------------------------------------------------------- Name : gnash Product : Fedora 15 Version : 0.8.10 Release : 2.fc15 URL : http://www.gnu.org/software/gnash/ Summary : GNU flash movie player Description : Gnash is capable of reading up to SWF v9 files and op-codes, but primarily supports SWF v7, with better SWF v8 and v9 support under heavy development. Gnash includes initial parser support for SWF v8 and v9. Not all ActionScript 2 classes are implemented yet, but all of the most heavily used ones are. Many ActionScript 2 classes are partially implemented; there is support for all of the commonly used methods of each class. -------------------------------------------------------------------------------- Update Information: Fix CVE-2012-1175 -------------------------------------------------------------------------------- ChangeLog: * Thu Mar 15 2012 Hicham HAOUARI <hicham.haouari@gmail.com> - 1:0.8.10-2 - Fix CVE-2012-1175 ( rhbz #803443 #803444 ) * Mon Feb 27 2012 Hicham HAOUARI <hicham.haouari@gmail.com> - 1:0.8.10-1 - Update to 0.8.10 - Drop patches backported from upstream * Thu Jan 26 2012 Hicham HAOUARI <hicham.haouari@gmail.com> - 1:0.8.9-9 - Add unistd.h header ( http://www.mail-archive.com/gcc-bugs@gcc.gnu.org/msg33879... ) - Backport patch from upstream that replaces xulrunner-headers patch ( http://git.savannah.gnu.org/gitweb/?p=gnash.git;a=commit;... ) * Fri Jan 13 2012 Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 1:0.8.9-8 - Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild * Mon Nov 21 2011 Daniel Drake <dsd@laptop.org> - 1:0.8.9-7 - Add patch to fix compile with new xulrunner * Mon Nov 21 2011 Peter Robinson <pbrobinson@fedoraproject.org> - 1:0.8.9-6 - Rebuild for boost 1.48 * Tue Jul 26 2011 Peter Robinson <pbrobinson@fedoraproject.org> - 1:0.8.9-5 - Rebuild for boost 1.47 -------------------------------------------------------------------------------- References: [ 1 ] Bug #803443 - CVE-2012-1175 gnash: integer overflow vulnerability https://bugzilla.redhat.com/show_bug.cgi?id=803443 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update gnash' at the command line. For more information, refer to "Managing Software with yum", available at http://docs.fedoraproject.org/yum/. All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list package-announce@lists.fedoraproject.org https://admin.fedoraproject.org/mailman/listinfo/package-...


(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds