Fedora has issued an advisory today (January 24):
The issues are fixed upstream in 3.8.2. Freeze push requested for Cauldron.
These are the same issues we just fixed in Bug 19952.
The patch is checked into Mageia 5 SVN.
Patched package uploaded for Mageia 5.
Updated audacious-plugins packages fix security vulnerabilities:
Chris Evans discovered that incorrect emulation of the SPC700 audio
co-processor of the Super Nintendo Entertainment System allows the execution
of arbitrary code if a malformed SPC music file is opened (CVE-2016-9957,
CVE-2016-9958, CVE-2016-9959, CVE-2016-9960, CVE-2016-9961).
These issues were previously fixed in MGASA-2016-0428 in the game-music-emu
library, but audacious-plugins contains a decoder built with a bundled
copy, which has been patched to fix the issues.
Updated packages in core/updates_testing:
What about the tainted version?
I've added the advisory to svn with ...
Either the tainted version needs to be added or the advisory in svn updated.
Ugh, tainted is annoying. It's on its way. Thanks for catching it.
advisory feedback =>
I first added Tainted Updates Testing repos (the regular Tainted I have always), then searched for audacious, but I did not get audacious-wavpack, audacious-jack , audacious-fluidsynth nor audacious-sid in any version. belnet is usually a day later, but not that much and it carries the other updates correctly.
They are there. Perhaps you forgot to update the tainted/updates repo after enabling it.
(In reply to James Kerr from comment #5)
> They are there. Perhaps you forgot to update the tainted/updates repo after
> enabling it.
Meant to write tainted/updates-testing
I routinely refresh all repos before starting a test session, and then still, the tainted audacious-adplug was found, but not the ones I indicated. But now indeed all are present.
MGA5-32 on Asus A6000VM Xfce
No installation issues.
$ strace -o audacious.txt audacious
Played CD and checked in trace that plugins are called: OK
David - did you get tainted updated as well?
Tested tainted plugins
# urpmi audacious-plugins
Package audacious-plugins-3.5.2-2.1.mga5.tainted.i586 is already installed
installing audacious-pulse-3.5.2-2.1.mga5.tainted.i586.rpm from /var/cache/urpmi/rpms
sounds and different effects available are working properly.
To satisfy dependencies, the following package(s) also need to be installed:
6.6MB of additional disk space will be used.
Jammed out to âFrom the Beginningâ in FLAC by Emerson, Lake & Palmer. Working as designed
advisory MGA5-32-OK =>
advisory MGA5-32-OK MGA5-64-OK
An update for this issue has been pushed to the Mageia Updates repository.