Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 836564

Summary: <media-libs/libmediainfo-22.03: parsing/crash bugs
Product: Gentoo Security Reporter: John Helmert III <ajak>
Component: VulnerabilitiesAssignee: Gentoo Security <security>
Status: CONFIRMED ---    
Severity: minor CC: media-video
Priority: Normal    
Version: unspecified   
Hardware: All   
OS: Linux   
URL: https://github.com/MediaArea/MediaInfo/releases/tag/v22.03
Whiteboard: B3 [glsa]
Package list:
Runtime testing required: ---
Bug Depends on: 868030    
Bug Blocks:    

Description John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2022-03-31 20:06:16 UTC
A couple potentially security-relevant fixes at URL,
"Dolby E: fix crash with some invalid streams
...
Several other parsing bug/crash fixes
Fix of random crash at startup"

Please bump to 22.03.
Comment 1 Larry the Git Cow gentoo-dev 2022-04-22 01:03:19 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=bcddbfec2336c7df227057df1e86a6c3806aa684

commit bcddbfec2336c7df227057df1e86a6c3806aa684
Author:     Sam James <sam@gentoo.org>
AuthorDate: 2022-04-22 01:02:52 +0000
Commit:     Sam James <sam@gentoo.org>
CommitDate: 2022-04-22 01:03:12 +0000

    media-libs/libzen: add 0.4.39
    
    Closes: https://bugs.gentoo.org/831208
    Bug: https://bugs.gentoo.org/836564
    Signed-off-by: Sam James <sam@gentoo.org>

 media-libs/libzen/Manifest             |  1 +
 media-libs/libzen/libzen-0.4.39.ebuild | 67 ++++++++++++++++++++++++++++++++++
 2 files changed, 68 insertions(+)

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=8daab09542a10a5615fc5a59627fa4065933d2d5

commit 8daab09542a10a5615fc5a59627fa4065933d2d5
Author:     Sam James <sam@gentoo.org>
AuthorDate: 2022-04-22 01:01:56 +0000
Commit:     Sam James <sam@gentoo.org>
CommitDate: 2022-04-22 01:03:11 +0000

    media-video/mediainfo: add 22.03
    
    Closes: https://bugs.gentoo.org/831208
    Bug: https://bugs.gentoo.org/836564
    Signed-off-by: Sam James <sam@gentoo.org>

 media-video/mediainfo/Manifest               |  1 +
 media-video/mediainfo/mediainfo-22.03.ebuild | 86 ++++++++++++++++++++++++++++
 2 files changed, 87 insertions(+)

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=84e89f4b97cd9ec3b45667c7ec211d9d1f0579ea

commit 84e89f4b97cd9ec3b45667c7ec211d9d1f0579ea
Author:     Sam James <sam@gentoo.org>
AuthorDate: 2022-04-22 00:58:05 +0000
Commit:     Sam James <sam@gentoo.org>
CommitDate: 2022-04-22 01:03:11 +0000

    media-libs/libmediainfo: add 22.03
    
    Closes: https://bugs.gentoo.org/831208
    Bug: https://bugs.gentoo.org/836564
    Signed-off-by: Sam James <sam@gentoo.org>

 media-libs/libmediainfo/Manifest                  |  1 +
 media-libs/libmediainfo/libmediainfo-22.03.ebuild | 84 +++++++++++++++++++++++
 2 files changed, 85 insertions(+)
Comment 2 jospezial 2023-07-31 14:38:29 UTC
The affected versions are long gone from the tree.
Can this bug close?