Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 384095 - <media-video/ffmpeg-0.7.5 Multiple Vulnerabilities
Summary: <media-video/ffmpeg-0.7.5 Multiple Vulnerabilities
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Gentoo Security
URL: https://secunia.com/advisories/46134/
Whiteboard: B2 [glsa]
Keywords:
Depends on:
Blocks: 382301
  Show dependency tree
 
Reported: 2011-09-22 14:51 UTC by Agostino Sarubbo
Modified: 2013-10-25 19:11 UTC (History)
0 users

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Agostino Sarubbo gentoo-dev 2011-09-22 14:51:27 UTC
From secunia security advisor at $URL:

Description:
The vulnerabilities are caused due to various errors related to the "svq3_get_se_golomb()" function and can be exploited by tricking a user into opening specially crafted media files.

The vulnerabilities are reported in versions prior to 0.7.5


Solution:
Update to version 0.7.5

@maintainer
Please also remove 0.8.x version and bump 0.8.4
Comment 1 Alexis Ballier gentoo-dev 2011-09-22 15:28:01 UTC
(In reply to comment #0)
> Solution:
> Update to version 0.7.5
> 
> @maintainer
> Please also remove 0.8.x version and bump 0.8.4

done some hours ago
Comment 2 Alexis Ballier gentoo-dev 2011-09-22 15:33:32 UTC
oh and i prefer removing matching 0.7.x and 0.8.x-1 versions together, meaning eg 0.8.3 goes away with 0.7.4
Comment 3 Agostino Sarubbo gentoo-dev 2011-09-22 16:37:09 UTC
Thanks Alexis.


Arches please test and mark stable:

=media-video/ffmpeg-0.7.5

Target KEYWORDS : "alpha amd64 arm hppa ia64 ppc ppc64 sparc x86"
Comment 4 Agostino Sarubbo gentoo-dev 2011-09-22 20:34:23 UTC
amd64 fine, QA about dodoc is not a regression
Comment 5 Tony Vroon (RETIRED) gentoo-dev 2011-09-22 20:36:43 UTC
+  22 Sep 2011; Tony Vroon <chainsaw@gentoo.org> ffmpeg-0.7.5.ebuild:
+  Marked stable on based on arch testing by Agostino "ago" Sarubbo in security
+  bug #384095.
Comment 6 Paweł Hajdan, Jr. (RETIRED) gentoo-dev 2011-09-25 04:28:50 UTC
x86 stable
Comment 7 Jeroen Roovers (RETIRED) gentoo-dev 2011-09-27 15:36:43 UTC
Stable for HPPA.
Comment 8 Kacper Kowalik (Xarthisius) (RETIRED) gentoo-dev 2011-09-28 03:18:22 UTC
ppc/ppc64 stable
Comment 9 Raúl Porcel (RETIRED) gentoo-dev 2011-10-02 13:40:10 UTC
alpha/arm/ia64/sparc stable
Comment 10 Tim Sammut (RETIRED) gentoo-dev 2011-10-02 14:25:35 UTC
Thanks, everyone. Added to existing GLSA request.
Comment 11 Alexis Ballier gentoo-dev 2013-08-14 21:14:18 UTC
nothing left to do for media-video@
Comment 12 GLSAMaker/CVETool Bot gentoo-dev 2013-10-25 19:11:20 UTC
This issue was resolved and addressed in
 GLSA 201310-12 at http://security.gentoo.org/glsa/glsa-201310-12.xml
by GLSA coordinator Sean Amoss (ackle).