Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 446468 - media-video/avidemux bundles vulnerable ffmpeg-0.9
Summary: media-video/avidemux bundles vulnerable ffmpeg-0.9
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal normal with 1 vote (vote)
Assignee: Gentoo Media-video project
URL:
Whiteboard: B2 [ebuild tomask]
Keywords:
Depends on:
Blocks:
 
Reported: 2012-12-08 15:07 UTC by Michael Palimaka (kensington)
Modified: 2018-03-01 11:13 UTC (History)
6 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Michael Palimaka (kensington) gentoo-dev 2012-12-08 15:07:11 UTC
As discovered in bug #444262, media-video/avidemux-2.5.6-r2 bundles ffmpeg-0.9 which has a number of known security issues.

As discussed in the Qt team meeting, we intend to mask but still keep the vulnerable version, so this bug is just for tracking purposes.
Comment 1 Ben de Groot (RETIRED) gentoo-dev 2013-01-20 10:30:30 UTC
Package is now masked:

# Ben de Groot <yngwin@gentoo.org> (20 Jan 2013)
# 2.5* has known security and other issues due to bundled ffmpeg,
# see (bugs #446468 and #444262)
# 2.6* is masked for testing, and may have unknown issues due to bundled ffmpeg
# This package needs a new, dedicated maintainer. We voted for keeping it in
# the tree for now, so users who are willing to accept the known issues can
# still easily install it by unmasking this.
media-video/avidemux
Comment 2 Peter Weilbacher 2013-02-06 11:20:56 UTC
The problem seems to be that ffmpeg was bundled with avidemux because it was patched for avidemux (apparently to get frame accuracy for cutting). And in the 2.5 series FFmpeg was patched much more heavily (but for me resulted in much better handling of the videos, that's why I'm still sticking to that old version).

However, for avidemux-2.6 the Debian guys seem to have a patch that unbundles ffmpeg and uses the system library, see <http://anonscm.debian.org/gitweb/?p=pkg-multimedia/avidemux.git;a=blob;f=debian/patches/system-libav.patch;h=066c8ed832acc50ecc61a487ccbf00a4db4c8b0a;hb=HEAD>. There's more discussion at <http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=203211>.
Comment 3 Davide Pesavento (RETIRED) gentoo-dev 2013-12-26 02:28:56 UTC
Nothing to do for qt here.
Comment 4 Pacho Ramos gentoo-dev 2016-02-26 11:16:10 UTC
is there any reason for keeping the old 2.5.x series in the tree and not drop it completely?
Comment 5 Michał Górny archtester Gentoo Infrastructure gentoo-dev Security 2016-05-05 19:49:20 UTC
commit 974cf73f140789a1ca0537b5ed8185bb612ce3f5
Author: Michał Górny <mgorny@gentoo.org>
Date:   Thu May 5 21:44:25 2016

    package.mask: Remove stale mask for media-video/avidemux

commit 8bede8f34e19c76fbfdc0e56558d9f706cffb36b
Author: Michał Górny <mgorny@gentoo.org>
Date:   Thu May 5 21:43:30 2016

    media-video/avidemux, media-libs/avidemux*: remove old versions
Comment 6 Andreas Sturmlechner gentoo-dev 2017-11-12 14:46:20 UTC
So... this can be closed?