Bug 9616

Summary: ffmpeg new security issues fixed in 1.1.4
Product: Mageia Reporter: David Walser <luigiwalser>
Component: SecurityAssignee: Mageia Bug Squad <bugsquad>
Status: RESOLVED FIXED QA Contact: Sec team <security>
Severity: major    
Priority: Normal CC: fundawang
Version: Cauldron   
Target Milestone: ---   
Hardware: i586   
OS: Linux   
URL: http://lwn.net/Vulnerabilities/545986/
Whiteboard:
Source RPM: ffmpeg-1.1.2-1.mga3.src.rpm CVE:
Status comment:

Description David Walser 2013-04-04 18:54:31 CEST
Ubuntu has issued an advisory today (April 4):
http://www.ubuntu.com/usn/usn-1790-1/

This addresses 4 CVEs:
CVE-2013-0894, CVE-2013-2277, CVE-2013-2495, CVE-2013-2496

I don't know if these affect Mageia 2, but I don't see commits for them in git in the 0.10 branch, even though I do see recent commits, so I'm going to guess no for now.  See Bug 8881 for ffmpeg security issues affecting Mageia 2.

I do see CVE-2013-0894 and CVE-2013-2277 fixed in the 1.1 branch git log.  I believe the CVE-2013-249[56] are fixed in the iff and msrle changes from 3 weeks ago, even though those CVEs aren't referenced specifically in the commit messages.

Reproducible: 

Steps to Reproduce:
David Walser 2013-04-04 18:54:44 CEST

CC: (none) => fundawang

Comment 1 David Walser 2013-04-05 14:52:15 CEST
Fixed in fmpeg-1.1.4-1.mga3.  Thanks Funda!

Status: NEW => RESOLVED
Resolution: (none) => FIXED