Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 836564 - <media-libs/libmediainfo-22.03: parsing/crash bugs
Summary: <media-libs/libmediainfo-22.03: parsing/crash bugs
Status: CONFIRMED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor (vote)
Assignee: Gentoo Security
URL: https://github.com/MediaArea/MediaInf...
Whiteboard: B3 [glsa]
Keywords:
Depends on: 868030
Blocks:
  Show dependency tree
 
Reported: 2022-03-31 20:06 UTC by John Helmert III
Modified: 2023-11-24 20:19 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2022-03-31 20:06:16 UTC
A couple potentially security-relevant fixes at URL,
"Dolby E: fix crash with some invalid streams
...
Several other parsing bug/crash fixes
Fix of random crash at startup"

Please bump to 22.03.
Comment 1 Larry the Git Cow gentoo-dev 2022-04-22 01:03:19 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=bcddbfec2336c7df227057df1e86a6c3806aa684

commit bcddbfec2336c7df227057df1e86a6c3806aa684
Author:     Sam James <sam@gentoo.org>
AuthorDate: 2022-04-22 01:02:52 +0000
Commit:     Sam James <sam@gentoo.org>
CommitDate: 2022-04-22 01:03:12 +0000

    media-libs/libzen: add 0.4.39
    
    Closes: https://bugs.gentoo.org/831208
    Bug: https://bugs.gentoo.org/836564
    Signed-off-by: Sam James <sam@gentoo.org>

 media-libs/libzen/Manifest             |  1 +
 media-libs/libzen/libzen-0.4.39.ebuild | 67 ++++++++++++++++++++++++++++++++++
 2 files changed, 68 insertions(+)

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=8daab09542a10a5615fc5a59627fa4065933d2d5

commit 8daab09542a10a5615fc5a59627fa4065933d2d5
Author:     Sam James <sam@gentoo.org>
AuthorDate: 2022-04-22 01:01:56 +0000
Commit:     Sam James <sam@gentoo.org>
CommitDate: 2022-04-22 01:03:11 +0000

    media-video/mediainfo: add 22.03
    
    Closes: https://bugs.gentoo.org/831208
    Bug: https://bugs.gentoo.org/836564
    Signed-off-by: Sam James <sam@gentoo.org>

 media-video/mediainfo/Manifest               |  1 +
 media-video/mediainfo/mediainfo-22.03.ebuild | 86 ++++++++++++++++++++++++++++
 2 files changed, 87 insertions(+)

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=84e89f4b97cd9ec3b45667c7ec211d9d1f0579ea

commit 84e89f4b97cd9ec3b45667c7ec211d9d1f0579ea
Author:     Sam James <sam@gentoo.org>
AuthorDate: 2022-04-22 00:58:05 +0000
Commit:     Sam James <sam@gentoo.org>
CommitDate: 2022-04-22 01:03:11 +0000

    media-libs/libmediainfo: add 22.03
    
    Closes: https://bugs.gentoo.org/831208
    Bug: https://bugs.gentoo.org/836564
    Signed-off-by: Sam James <sam@gentoo.org>

 media-libs/libmediainfo/Manifest                  |  1 +
 media-libs/libmediainfo/libmediainfo-22.03.ebuild | 84 +++++++++++++++++++++++
 2 files changed, 85 insertions(+)
Comment 2 jospezial 2023-07-31 14:38:29 UTC
The affected versions are long gone from the tree.
Can this bug close?