Bug 31178 - VLC 3.0.18
Summary: VLC 3.0.18
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: RPM Packages (show other bugs)
Version: 8
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact:
URL:
Whiteboard: MGA8-64-OK
Keywords: advisory, validated_update
Depends on:
Blocks:
 
Reported: 2022-11-23 21:11 CET by David Walser
Modified: 2022-12-06 17:34 CET (History)
7 users (show)

See Also:
Source RPM: vlc-3.0.17.3-1.mga8.src.rpm
CVE:
Status comment:


Attachments

Description David Walser 2022-11-23 21:11:39 CET
VLC 3.0.18 has been released on November 22:
https://www.videolan.org/vlc/releases/3.0.18.html
https://code.videolan.org/videolan/vlc/-/raw/3.0.x/NEWS

This appears to just be a bugfix release, although crash fixes can be security fixes.

I updated it in Cauldron, but it doesn't build in Mageia 8 because of sndio:
http://pkgsubmit.mageia.org/uploads/failure/8/core/updates_testing/20221123192348.luigiwalser.duvel.3837288/log/vlc-3.0.18-1.mga8/build.i586.0.20221123192405.log

Unfortunately the newer version of sndio (which it's probably looking for) has major 7 instead of the 7.1 in the mga8 version.
Comment 1 Lewis Smith 2022-11-23 21:22:54 CET
Thanks DavidW for your efforts to date.
VLC is committed by different people at different times, so assigning this globally.

Assignee: bugsquad => pkg-bugs

Comment 2 Nicolas Salguero 2022-11-24 10:41:23 CET
Hi,

I disabled sndio in order to fix building.

Best regards,

Nico.

CC: (none) => nicolas.salguero

Comment 3 Nicolas Salguero 2022-11-24 11:00:56 CET
Suggested advisory:
========================

The updated packages fix several bugs.

References:
https://www.videolan.org/vlc/releases/3.0.18.html
https://code.videolan.org/videolan/vlc/-/raw/3.0.x/NEWS
========================

Updated packages in core/updates_testing:
========================
lib(64)vlc5-3.0.18-1.mga8
lib(64)vlccore9-3.0.18-1.mga8
lib(64)vlc-devel-3.0.18-1.mga8
svlc-3.0.18-1.mga8
vlc-3.0.18-1.mga8
vlc-plugin-aa-3.0.18-1.mga8
vlc-plugin-chromaprint-3.0.18-1.mga8
vlc-plugin-common-3.0.18-1.mga8
vlc-plugin-dv-3.0.18-1.mga8
vlc-plugin-flac-3.0.18-1.mga8
vlc-plugin-fluidsynth-3.0.18-1.mga8
vlc-plugin-gme-3.0.18-1.mga8
vlc-plugin-gnutls-3.0.18-1.mga8
vlc-plugin-jack-3.0.18-1.mga8
vlc-plugin-kate-3.0.18-1.mga8
vlc-plugin-libass-3.0.18-1.mga8
vlc-plugin-libnotify-3.0.18-1.mga8
vlc-plugin-lirc-3.0.18-1.mga8
vlc-plugin-lua-3.0.18-1.mga8
vlc-plugin-mod-3.0.18-1.mga8
vlc-plugin-mpc-3.0.18-1.mga8
vlc-plugin-ncurses-3.0.18-1.mga8
vlc-plugin-opengl-3.0.18-1.mga8
vlc-plugin-projectm-3.0.18-1.mga8
vlc-plugin-pulse-3.0.18-1.mga8
vlc-plugin-rist-3.0.18-1.mga8
vlc-plugin-samba-3.0.18-1.mga8
vlc-plugin-schroedinger-3.0.18-1.mga8
vlc-plugin-sdl-3.0.18-1.mga8
vlc-plugin-shout-3.0.18-1.mga8
vlc-plugin-sid-3.0.18-1.mga8
vlc-plugin-speex-3.0.18-1.mga8
vlc-plugin-theora-3.0.18-1.mga8
vlc-plugin-twolame-3.0.18-1.mga8
vlc-plugin-upnp-3.0.18-1.mga8
vlc-plugin-vdpau-3.0.18-1.mga8
vlc-plugin-zvbi-3.0.18-1.mga8

from SRPM:
vlc-3.0.18-1.mga8.src.rpm

Updated packages in tainted/updates_testing:
========================
lib(64)vlc5-3.0.18-1.mga8.tainted
lib(64)vlccore9-3.0.18-1.mga8.tainted
lib(64)vlc-devel-3.0.18-1.mga8.tainted
svlc-3.0.18-1.mga8.tainted
vlc-3.0.18-1.mga8.tainted
vlc-plugin-aa-3.0.18-1.mga8.tainted
vlc-plugin-chromaprint-3.0.18-1.mga8.tainted
vlc-plugin-common-3.0.18-1.mga8.tainted
vlc-plugin-dv-3.0.18-1.mga8.tainted
vlc-plugin-fdkaac-3.0.18-1.mga8.tainted
vlc-plugin-flac-3.0.18-1.mga8.tainted
vlc-plugin-fluidsynth-3.0.18-1.mga8.tainted
vlc-plugin-gme-3.0.18-1.mga8.tainted
vlc-plugin-gnutls-3.0.18-1.mga8.tainted
vlc-plugin-jack-3.0.18-1.mga8.tainted
vlc-plugin-kate-3.0.18-1.mga8.tainted
vlc-plugin-libass-3.0.18-1.mga8.tainted
vlc-plugin-libnotify-3.0.18-1.mga8.tainted
vlc-plugin-lirc-3.0.18-1.mga8.tainted
vlc-plugin-lua-3.0.18-1.mga8.tainted
vlc-plugin-mod-3.0.18-1.mga8.tainted
vlc-plugin-mpc-3.0.18-1.mga8.tainted
vlc-plugin-ncurses-3.0.18-1.mga8.tainted
vlc-plugin-opengl-3.0.18-1.mga8.tainted
vlc-plugin-projectm-3.0.18-1.mga8.tainted
vlc-plugin-pulse-3.0.18-1.mga8.tainted
vlc-plugin-rist-3.0.18-1.mga8.tainted
vlc-plugin-samba-3.0.18-1.mga8.tainted
vlc-plugin-schroedinger-3.0.18-1.mga8.tainted
vlc-plugin-sdl-3.0.18-1.mga8.tainted
vlc-plugin-shout-3.0.18-1.mga8.tainted
vlc-plugin-sid-3.0.18-1.mga8.tainted
vlc-plugin-speex-3.0.18-1.mga8.tainted
vlc-plugin-theora-3.0.18-1.mga8.tainted
vlc-plugin-twolame-3.0.18-1.mga8.tainted
vlc-plugin-upnp-3.0.18-1.mga8.tainted
vlc-plugin-vdpau-3.0.18-1.mga8.tainted
vlc-plugin-zvbi-3.0.18-1.mga8.tainted

from SRPM:
vlc-3.0.18-1.mga8.tainted.src.rpm

Assignee: pkg-bugs => qa-bugs
Status: NEW => ASSIGNED

Comment 4 Herman Viaene 2022-11-24 15:18:56 CET
MGA8-64 MATE on Acer Aspire 5253
Installed all tainted stuff OK.
Played mp4, mpeg, avi, mov all OK.

CC: (none) => herman.viaene

Comment 5 Jose Manuel López 2022-11-24 16:30:19 CET
Installed in Mga8-x64 Plasma on Slimbook Pro X15 AMD
All ok for the moment. 
- Audio mp3, mp4 ok.
- Video mkv, avi, mp4, ok.
- Settings and spanish translation, ok.
- Convert video ok.

Flags: (none) => in_errata7-
CC: (none) => joselp

David Walser 2022-11-24 17:12:58 CET

Flags: in_errata7- => (none)

Comment 6 Brian Rockwell 2022-11-25 04:01:08 CET
$ uname -a
Linux localhost.localdomain 5.15.79-desktop-1.mga8 #1 SMP Wed Nov 16 16:07:06 UTC 2022 x86_64 x86_64 x86_64 GNU/Linux

Physical hardware - using pulse audio



The following 35 packages are going to be installed:

- fonts-ttf-bitstream-vera-1.10-18.mga8.noarch
- lib64aribb25_0-0.2.7-1.mga8.x86_64
- lib64cddb2-1.3.2-21.mga8.x86_64
- lib64crystalhd3-0-0.20110315.13.mga8.x86_64
- lib64dca0-0.0.7-1.mga8.tainted.x86_64
- lib64dvbpsi10-1.3.3-2.mga8.x86_64
- lib64dvdcss2-1.4.2-3.mga8.tainted.x86_64
- lib64ebml5-1.4.2-1.mga8.x86_64
- lib64faad2-2.10.0-1.mga8.tainted.x86_64
- lib64fdk-aac2-2.0.1-2.mga8.tainted.x86_64
- lib64matroska7-1.6.2-1.mga8.x86_64
- lib64protobuf-lite25-3.14.0-1.mga8.x86_64
- lib64vlc5-3.0.18-1.mga8.tainted.x86_64
- lib64vlccore9-3.0.18-1.mga8.tainted.x86_64
- lib64x264_157-0.157-0.20191217.stable.2.mga8.tainted.x86_64
- lib64x265_192-3.4-1.mga8.tainted.x86_64
- lib64xcb-composite0-1.14-1.mga8.x86_64
- lib64xcb-xv0-1.14-1.mga8.x86_64
- libcrystalhd-common-0-0.20110315.13.mga8.x86_64
- vlc-3.0.18-1.mga8.tainted.x86_64
- vlc-plugin-aa-3.0.18-1.mga8.tainted.x86_64
- vlc-plugin-common-3.0.18-1.mga8.tainted.x86_64
- vlc-plugin-dv-3.0.18-1.mga8.tainted.x86_64
- vlc-plugin-fdkaac-3.0.18-1.mga8.tainted.x86_64
- vlc-plugin-flac-3.0.18-1.mga8.tainted.x86_64
- vlc-plugin-gnutls-3.0.18-1.mga8.tainted.x86_64
- vlc-plugin-libass-3.0.18-1.mga8.tainted.x86_64
- vlc-plugin-libnotify-3.0.18-1.mga8.tainted.x86_64
- vlc-plugin-lua-3.0.18-1.mga8.tainted.x86_64
- vlc-plugin-opengl-3.0.18-1.mga8.tainted.x86_64
- vlc-plugin-pulse-3.0.18-1.mga8.tainted.x86_64
- vlc-plugin-samba-3.0.18-1.mga8.tainted.x86_64
- vlc-plugin-speex-3.0.18-1.mga8.tainted.x86_64
- vlc-plugin-theora-3.0.18-1.mga8.tainted.x86_64
- vlc-plugin-vdpau-3.0.18-1.mga8.tainted.x86_64

68MB of additional disk space will be used.


Videos played, various formats of audio worked.

Working for me.

CC: (none) => brtians1

Comment 7 Thomas Andrews 2022-11-25 20:10:43 CET
MGA8-64 Plasma system. The tainted version was already installed.

Using qarepo, I downloaded and updated to the core versions, then played video and audio files of various formats, with no issues.

Then I again used qarepo, this time to get the tainted versions of the packages, and again updated and played the same files with no issues. 

I did not think of it before this point, but I tried playing a commercial DVD, and it worked perfectly. Then, I tried the core update again, this time in a VirtualBox guest. It still played the DVD with no problem. Then I removed lib64dvdcss2, a dependency of the tainted version of vlc, but not the core version. The DVD would not play correctly; video was blank. Updating to the tainted version drew back in lib64dvdcss2, and the DVD played correctly once more.

It looks good here. Giving it an OK, and validating. Advisory in comment 3.

Keywords: (none) => validated_update
Whiteboard: (none) => MGA8-64-OK
CC: (none) => andrewsfarm, sysadmin-bugs

Dave Hodgins 2022-11-27 19:04:45 CET

Keywords: (none) => advisory
CC: (none) => davidwhodgins

Comment 8 Mageia Robot 2022-11-27 21:53:14 CET
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGAA-2022-0152.html

Status: ASSIGNED => RESOLVED
Resolution: (none) => FIXED

Comment 9 David Walser 2022-12-02 03:37:02 CET
Release notes have been posted, as has a security advisory:
https://www.videolan.org/security/sb-vlc3018.html

This update fixed four security issues, including CVE-2022-41325.
Comment 10 David Walser 2022-12-06 17:34:40 CET
Debian-LTS has issued an advisory for this on December 3:
https://www.debian.org/lts/security/2022/dla-3216

Note You need to log in before you can comment on or make changes to this bug.