Bug 31067 - FFmpeg 4.3.5
Summary: FFmpeg 4.3.5
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 8
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA8-64-OK
Keywords: advisory, has_procedure, validated_update
Depends on:
Blocks:
 
Reported: 2022-11-02 21:32 CET by David Walser
Modified: 2022-11-08 20:46 CET (History)
5 users (show)

See Also:
Source RPM: ffmpeg-4.3.4-1.mga8.src.rpm
CVE:
Status comment:


Attachments

Description David Walser 2022-11-02 21:32:17 CET
FFmpeg 4.3.5 has been released on October 10:
https://git.ffmpeg.org/gitweb/ffmpeg.git/shortlog/n4.3.5

Note that there are core and tainted builds for this package.

Testing procedure:
https://bugs.mageia.org/show_bug.cgi?id=8065#c6
https://bugs.mageia.org/show_bug.cgi?id=14042#c6

Advisory:
========================

Updated ffmpeg packages fix security vulnerabilities:

This update provides ffmpeg version 4.3.5, which fixes several security
vulnerabilities and other bugs which were corrected upstream.

References:
https://git.ffmpeg.org/gitweb/ffmpeg.git/shortlog/n4.3.5
http://ffmpeg.org/download.html
http://ffmpeg.org/security.html
========================

Updated packages in {core,tainted}/updates_testing:
========================
ffmpeg-4.3.5-1.mga8
libavcodec58-4.3.5-1.mga8
libavfilter7-4.3.5-1.mga8
libavformat58-4.3.5-1.mga8
libavutil56-4.3.5-1.mga8
libffmpeg-devel-4.3.5-1.mga8
libswscaler5-4.3.5-1.mga8
libavresample4-4.3.5-1.mga8
libswresample3-4.3.5-1.mga8
libpostproc55-4.3.5-1.mga8
libffmpeg-static-devel-4.3.5-1.mga8

from ffmpeg-4.3.5-1.mga8.src.rpm
Comment 1 David Walser 2022-11-02 21:33:21 CET
Debian has issued an advisory for this on November 1:
https://www.debian.org/security/2022/dsa-5268

Just noting that.  It has no useful details.

Also, the CVE-2020-21041 listed at http://ffmpeg.org/security.html was already fixed by us in Bug 29256.

Keywords: (none) => has_procedure

Comment 2 Herman Viaene 2022-11-03 10:59:59 CET
MGA8-64 MATE on Acer Aspire 5253
No installation issues.
I don't know what to think of this: playing an mp4 file (recording I made from webcam) plays OK with other players (parole, vlc, Video frim MATE), but with mplayer the image lags a lot behind the sound, in the end about 4seconds on a 17 seconds clip.

CC: (none) => herman.viaene

Comment 3 Len Lawrence 2022-11-04 19:19:06 CET
mga8, x64
Installed tainted packages and ran a few tests, like conversion from avi to mp4 and adding a subtitle track to a video.

Updated the packages using qarepo with tainted set.

Ran similar tests.
$ ffmpeg -i Jane_live_cartoon.avi -an -scodec copy Jane.mp4
$ ll Jane*
-rw-r--r-- 1 lcl lcl 1101895588 Dec 23  2021 Jane_live_cartoon.avi
-rw-r--r-- 1 lcl lcl  213237930 Nov  4 17:21 Jane.mp4
No sound with vlc or mplayer for Jane.mp4 - may be a regression but more likely lack of parameters or error in the parameters given.

$ ffmpeg -n -i Winterwatch.mp4 -f srt -i Winterwatch.srt -c:s mov_text -metadata:s:s:0  language=eng -c:v copy -c:a copy sameagain.mp4

sameagain.mp4 played fine with vlc and subtitles were available.  In mplayer the subtitles come up automatically.

$ ffmpeg -i 'Long as I Can See the Light.wav' creedence.mp3
The mp3 file plays OK in mplayer.
No trouble converting an AVI file to MP3 format and playing it with mplayer.

Leaving this open for a while for others to test.

CC: (none) => tarazed25

Comment 4 Thomas Andrews 2022-11-07 01:21:30 CET
Using "urpmq --whatrequires ffmpeg" came up with something called "ffmulticonverter," a gui front end for ffmpeg. It's supposed to be able to convert between any file format that ffmpeg uses. Intrigued, I decided to use it for my test.

I used qarepo to first get and test the core versions of these updates, then the tainted versions. Using ffmulticonverter, I was able to convert between mp4, avi, webm, and mkv formats. 

Most files worked as expected, but there were some conversions that were unexpected, involving one mkv source video. Converting it to mp4 with the default settings was successful, with good video, but there was no audio. Converting to avi was also successful, with good audio, but the video quality was terrible.

Other conversions using the same formats were fine, so I believe the issues were due to something unique to that video, or were caused by my using the default settings.

Giving this an OK, and validating. Advisory in Comment 0.

Whiteboard: (none) => MGA8-64-OK
CC: (none) => andrewsfarm, sysadmin-bugs
Keywords: (none) => validated_update

Dave Hodgins 2022-11-08 16:01:04 CET

CC: (none) => davidwhodgins
Keywords: (none) => advisory

Comment 5 Mageia Robot 2022-11-08 20:46:01 CET
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2022-0416.html

Status: NEW => RESOLVED
Resolution: (none) => FIXED


Note You need to log in before you can comment on or make changes to this bug.