Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 177008 - media-video/xine-ui-0.99.5 fixes security issues
Summary: media-video/xine-ui-0.99.5 fixes security issues
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High normal
Assignee: Gentoo Security
URL: http://sourceforge.net/project/showno...
Whiteboard: B? [noglsa] jaervosz
Keywords:
: 173952 (view as bug list)
Depends on:
Blocks:
 
Reported: 2007-05-04 08:47 UTC by Carsten Lohrke (RETIRED)
Modified: 2007-05-20 16:07 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Carsten Lohrke (RETIRED) gentoo-dev 2007-05-04 08:47:58 UTC
Security issues with playlists are fixed, therefore upgrade is recommended.
Furthermore: crashes, memleaks and bugs are fixed, functional enhancements and
features added, appearance of non-skinned windows harmonized (with more space,
useful also for translations), translations updated. See ChangeLog for more.

http://sourceforge.net/project/shownotes.php?release_id=505758
Comment 1 Samuli Suominen (RETIRED) gentoo-dev 2007-05-05 05:00:27 UTC
0.99.5 is in tree.
Comment 2 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2007-05-05 06:38:23 UTC
Thx Samuli.

Arhces please test and mark stable. Target keywords are:

xine-ui-0.99.5.ebuild:KEYWORDS="alpha amd64 ~hppa ppc ppc64 sparc x86 ~x86-fbsd"
Comment 3 Tobias Scherbaum (RETIRED) gentoo-dev 2007-05-05 10:44:55 UTC
ppc stable
Comment 4 Raúl Porcel (RETIRED) gentoo-dev 2007-05-05 11:15:04 UTC
x86 stable
Comment 5 Markus Rothe (RETIRED) gentoo-dev 2007-05-05 13:11:53 UTC
ppc64 stable
Comment 6 Pacho Ramos gentoo-dev 2007-05-05 20:51:09 UTC
Works ok on amd64:

Portage 2.1.2.2 (default-linux/amd64/2006.1, gcc-4.1.1, glibc-2.5-r0, 2.6.20-ck1 x86_64)
=================================================================
System uname: 2.6.20-ck1 x86_64 AMD Athlon(tm) 64 Processor 3200+
Gentoo Base System release 1.12.9
Timestamp of tree: Sat, 05 May 2007 10:20:01 +0000
ccache version 2.4 [enabled]
dev-java/java-config: 1.3.7, 2.0.31-r5
dev-lang/python:     2.4.3-r4
dev-python/pycrypto: 2.0.1-r5
dev-util/ccache:     2.4-r7
sys-apps/sandbox:    1.2.17
sys-devel/autoconf:  2.13, 2.61
sys-devel/automake:  1.4_p6, 1.5, 1.6.3, 1.7.9-r1, 1.8.5-r3, 1.9.6-r2, 1.10
sys-devel/binutils:  2.16.1-r3
sys-devel/gcc-config: 1.3.16
sys-devel/libtool:   1.5.22
virtual/os-headers:  2.6.19.2-r2
ACCEPT_KEYWORDS="amd64"
AUTOCLEAN="yes"
CBUILD="x86_64-pc-linux-gnu"
CFLAGS="-march=k8 -O2 -pipe -msse3"
CHOST="x86_64-pc-linux-gnu"
CONFIG_PROTECT="/etc /usr/kde/3.5/env /usr/kde/3.5/share/config /usr/kde/3.5/shutdown /usr/share/X11/xkb /usr/share/config"
CONFIG_PROTECT_MASK="/etc/env.d /etc/env.d/java/ /etc/gconf /etc/java-config/vms/ /etc/revdep-rebuild /etc/splash /etc/terminfo /etc/texmf/web2c"
CXXFLAGS="-march=k8 -O2 -pipe -msse3"
DISTDIR="/usr/distfiles"
FEATURES="autoaddcvs ccache collision-protect cvs distlocks metadata-transfer multilib-strict parallel-fetch sandbox sfperms strict"
GENTOO_MIRRORS="http://ftp.belnet.be/mirror/rsync.gentoo.org/gentoo/"
LANG="es_ES.UTF-8"
LC_ALL="es_ES.UTF-8"
LINGUAS="es en_US"
MAKEOPTS="-j2"
PKGDIR="/usr/portage/packages"
PORTAGE_RSYNC_EXTRA_OPTS="--exclude-from=/etc/portage/rsync_excludes"
PORTAGE_RSYNC_OPTS="--recursive --links --safe-links --perms --times --compress --force --whole-file --delete --delete-after --stats --timeout=180 --exclude=/distfiles --exclude=/local --exclude=/packages --filter=H_**/files/digest-*"
PORTAGE_TMPDIR="/var/tmp"
PORTDIR="/usr/portage"
PORTDIR_OVERLAY="/usr/portage/local/layman/musicbrainz /usr/portage/local/layman/sunrise /usr/local/portage"
SYNC="rsync://rsync.europe.gentoo.org/gentoo-portage"
USE="X a52 aac acpi alsa amd64 arts asf audiofile bash-completion beagle bitmap-fonts bzip2 bzlib cairo caps cdb cdda cddb cdparanoia cdr cli cpdflib cpudetection cracklib cross crypt cups curl dbus dga divx4linux dlloader dri dts dvb dvd dvdr dvdread encode erandom escreen esd evo evolution exif fam fbcon flac foomaticdb fortran ftp galago gb gcj ggi gif gimp gimpprint glitz glut glx gnome gnome-print gphoto2 gpm gstreamer gtk gtk2 gtkhtml hal iconv idn imagemagick imlib isdnlog ithreads jabber java jpeg kde kdeenablefinal kdehiddenvisibility latex lcms libg++ libnotify logrotate mad madwifi midi mikmod mime mng mono motif mp3 mpeg mpi mplayer musepack musicbrainz nas nautilus ncurses nethack network nls nocardbus nptl nptlonly nvidia ogg oggvorbis openal opengl pam pcre pdf perl pic plotutils png posix ppds pppd python qt3 qt4 quicktime readline reflection rtc ruby scanner sdl seamonkey session slang slp sockets spell spl sse3 ssl startup-notification svg sysvipc tcltk tcpd tetex theora threads tiff timidity tk totem trayicon truetype truetype-fonts type1-fonts unicode usb v4l v4l2 vcd videos vim vorbis wma wmf xcomposite xine xml xml2 xorg xpm xv xvid zlib" ALSA_CARDS="ali5451 als4000 atiixp atiixp-modem bt87x ca0106 cmipci emu10k1x ens1370 ens1371 es1938 es1968 fm801 hda-intel intel8x0 intel8x0m maestro3 trident usb-audio via82xx via82xx-modem ymfpci" ALSA_PCM_PLUGINS="adpcm alaw asym copy dmix dshare dsnoop empty extplug file hooks iec958 ioplug ladspa lfloat linear meter mulaw multi null plug rate route share shm softvol" ELIBC="glibc" INPUT_DEVICES="keyboard mouse" KERNEL="linux" LCD_DEVICES="bayrad cfontz cfontz633 glk hd44780 lb216 lcdm001 mtxorb ncurses text" LINGUAS="es en_US" USERLAND="GNU" VIDEO_CARDS="nvidia nv vesa fbdev vga"
Unset:  CTARGET, EMERGE_DEFAULT_OPTS, INSTALL_MASK, LDFLAGS, PORTAGE_COMPRESS, PORTAGE_COMPRESS_FLAGS

Comment 7 Gustavo Zacarias (RETIRED) gentoo-dev 2007-05-07 13:33:42 UTC
sparc stable.
Comment 8 Samuli Suominen (RETIRED) gentoo-dev 2007-05-10 14:31:39 UTC
*** Bug 173952 has been marked as a duplicate of this bug. ***
Comment 9 Samuli Suominen (RETIRED) gentoo-dev 2007-05-10 14:35:00 UTC
bleh, hppa never had stable keyword here. srry about bugspam.
Comment 10 Jose Luis Rivero (yoswink) (RETIRED) gentoo-dev 2007-05-11 09:07:24 UTC
alpha stable.
Comment 11 Steve Dibb (RETIRED) gentoo-dev 2007-05-11 14:50:46 UTC
amd64 stable
Comment 12 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2007-05-19 22:51:23 UTC
I'm not really sure what security issues this fix. The only detail I can dig up is:

Fixed security issues related to playlist files (thanks to Chris Ries)

With only that information I tend to vote NO. If anyone have further details feel free to provide them:)
Comment 13 Daniel Black (RETIRED) gentoo-dev 2007-05-19 23:01:13 UTC
if they are talking about:
 Fixed segfaults when appending files to playlist, current play not interrupted
 when appending files to playlist, only file name displayed in playlist dialog to better fit into the dialog box. Thanks to Michael Hughes for this patch
(from Changes in above URL)
no glsa
Comment 14 Vic Fryzel (shellsage) (RETIRED) gentoo-dev 2007-05-20 15:29:24 UTC
I vote no.
Comment 15 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2007-05-20 16:07:40 UTC
Closing with NO GLSA with current level of information.