Bug 217609 - media-plugins/gst-plugins-speex <0.10.7-r1 speex implementations insufficient boundary checks
|
Bug#:
217609
|
Product: Gentoo Security
|
Version: unspecified
|
Platform: All
|
|
OS/Version: Linux
|
Status: RESOLVED
|
Severity: normal
|
Priority: P2
|
|
Resolution: WONTFIX
|
Assigned To: security@gentoo.org
|
Reported By: vorlon@gentoo.org
|
|
Component: Vulnerabilities
|
|
|
URL:
|
|
Summary: media-plugins/gst-plugins-speex <0.10.7-r1 speex implementations insufficient boundary checks
|
|
Keywords:
|
|
Status Whiteboard: B2 []
|
|
Opened: 2008-04-14 09:42 0000
|
I wonder how this affects media-plugins/gst-plugins-speex
+*gst-plugins-speex-0.10.7-r1 (14 Apr 2008)
+
+ 14 Apr 2008; Samuli Suominen <drac@gentoo.org>
+ +files/gst-plugins-speex-0.10.7-sec.patch,
+ +gst-plugins-speex-0.10.7-r1.ebuild:
+ Fix for security #217609.
Arch Security Liaisons, please test and mark stable:
=media-plugins/gst-plugins-speex-0.10.7-r1
Target keywords : "ppc ppc64 release sparc"
CC'ing current Liaisons:
ppc : dertobi123
ppc64 : corsair
release : pva
sparc : fmccor
corsair, fmccor, and others. because this needs gstreamer 0.10.17, make sure
you stable also newer version of gst-plugins-ugly, 0.10.6-r1 or newer is OK.
this is to avoid blockers, repoman won't reveal this.
Sparc stable for gst-plugins-speex <0.10.7-r1.
This requires also sparc stable for:
gstreamer-0.10.7
gst-plugins-base-0.10.7
gst-plugins-ugly-10.6-r1
All done.
This will be fixed with the speex update in bug 217715, keeping open until the
GLSA has been released.
speex has been sent as GLSA 200804-17, this also fixes this bug.