Summary: | media-libs/xine-lib: Malformed MPEG Stream Buffer Overflow (CVE-2006-1664) | ||
---|---|---|---|
Product: | Gentoo Security | Reporter: | Raphael Marichez (Falco) (RETIRED) <falco> |
Component: | Vulnerabilities | Assignee: | Gentoo Security <security> |
Status: | RESOLVED FIXED | ||
Severity: | major | CC: | fbossi, flameeyes |
Priority: | High | ||
Version: | unspecified | ||
Hardware: | All | ||
OS: | Linux | ||
URL: | http://www.securityfocus.com/bid/17370 | ||
Whiteboard: | A2 [glsa] Falco | ||
Package list: | Runtime testing required: | --- |
Description
Raphael Marichez (Falco) (RETIRED)
2006-04-04 16:35:04 UTC
*** Bug 128855 has been marked as a duplicate of this bug. *** Hi, it is an A2. We should have acted now. Sadly, AFAIK, no fix is available upstream and no other distrib has released any update yet. I'm not aware of any evolution on this issue. Has someone any information ? FYI the target delay is counted once the bug has left upstream status, since we can't really fix it before. Sorry :) Then let's wait and see ! Upstream is late The 1.1.2_pre20060328 snapshot seems to be unaffected, at least the given concept stream doesn't crash xine at all (while it does on 1.1.1-r5). Despite being a CVS snapshot, that version appears to me quite stable, I'm using it almost daily, for both Kaffeine (video playing) and amaroK (audio), and I haven't hit any kind of problem (it might be considered more working than the current 1.1.1 version in some aspects, like MKV demuxing). At this point, I can think of removing it from package.mask and back in ~arch, to be tested for a while.. Okay I know I added -r1 just yesterday, but if this is going to be pushed stable, I'd rather see that marked stable as it _is_ finally stable. The main issue with xine (crashes when mad was disabled) is now fixed, and authenticated HTTP streams are fixed, too. I might say that this version is even more stable than the current stable :) So if a decision for pushing this has to be made, I suppose it should be okay at this point in time. Also, I didn't receive any "aaaargh my xine broke" kind of bugs after unmasking and going to ~arch. ok, here we go: arches, please test and stable 1.1.2_pre20060328-r1, thank you. (In reply to comment #8) > ok, here we go: arches, please test and stable 1.1.2_pre20060328-r1, thank you. alpha stable. sparc stable. x86 done stable on ppc64 stable on amd64 ppc stable Besides a gcc-4.1 bug, it's working perfectly on hppa :) Sorry for the last change. This one is ready for GLSA. arm & ia64 you can mark stable if you want, in order to benefit from the GLSA. GLSA 200604-16 arm, ia64 please don't forget to mark stable to benifit from the GLSA. |