Bug 4001 - mplayer missing security update for CVE-2009-4636 and CVE-2011-0722
Summary: mplayer missing security update for CVE-2009-4636 and CVE-2011-0722
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 1
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact:
URL:
Whiteboard:
Keywords: validated_update
Depends on:
Blocks:
 
Reported: 2012-01-01 22:00 CET by David Walser
Modified: 2012-01-14 15:25 CET (History)
8 users (show)

See Also:
Source RPM: mplayer-1.0-1.rc4.0.r32713.5.1.mga1.src.rpm
CVE:
Status comment:


Attachments
re-diffed patch for CVE-2009-4636 (652 bytes, patch)
2012-01-09 17:18 CET, David Walser
Details | Diff
re-diffed patch for CVE-2011-0722 (685 bytes, patch)
2012-01-09 17:25 CET, David Walser
Details | Diff
re-diffed patch for CVE-2011-0723 (539 bytes, patch)
2012-01-09 17:27 CET, David Walser
Details | Diff
re-diffed patch for ffmpeg-mov_bad_timings (google) (516 bytes, patch)
2012-01-09 17:32 CET, David Walser
Details | Diff
re-diffed patch for ffmpeg-mp3_outlen (google) (574 bytes, patch)
2012-01-09 17:37 CET, David Walser
Details | Diff
re-diffed patch for ffmpeg-vorbis_zero_samplerate (google) (526 bytes, patch)
2012-01-09 17:40 CET, David Walser
Details | Diff
diff for the SPEC file (1.93 KB, patch)
2012-01-09 18:01 CET, David Walser
Details | Diff

Description David Walser 2012-01-01 22:00:53 CET
Mandriva issued this advisory on May 16:
http://lists.mandriva.com/security-announce/2011-05/msg00011.php

Our package changelog shows a fix for CVE-2011-0723 but not the other ones in this bug.  These CVEs are due to the use of an internal copy of ffmpeg.  The blender package is also affected (Bug 3983).
Comment 1 Manuel Hiebel 2012-01-01 23:12:30 CET
Hi, thanks for reporting this bug.
As there is no maintainer for this package I added the committers in CC.

(Please set the status to 'assigned' if you are working on it)

CC: (none) => cjw, fundawang, mageia

David Walser 2012-01-04 00:00:44 CET

CC: (none) => dmorganec

Comment 2 David Walser 2012-01-09 00:39:57 CET
Whoever builds this, please delete the line that says --disable-dvbhead.  That configure option no longer exists.  Thanks.
Comment 3 David Walser 2012-01-09 17:18:11 CET
CVE-2010-3429 is already fixed in the version we have.
Comment 4 David Walser 2012-01-09 17:18:58 CET
Created attachment 1350 [details]
re-diffed patch for CVE-2009-4636
Comment 5 David Walser 2012-01-09 17:21:46 CET
CVE-2010-4704 is already fixed in the version we have.
Comment 6 David Walser 2012-01-09 17:25:02 CET
Created attachment 1351 [details]
re-diffed patch for CVE-2011-0722
Comment 7 David Walser 2012-01-09 17:27:19 CET
Created attachment 1352 [details]
re-diffed patch for CVE-2011-0723
Comment 8 David Walser 2012-01-09 17:32:47 CET
Created attachment 1353 [details]
re-diffed patch for ffmpeg-mov_bad_timings (google)
Comment 9 David Walser 2012-01-09 17:33:55 CET
ffmpeg-mov_dref_looping (google) is already fixed in the version we have.
Comment 10 David Walser 2012-01-09 17:37:42 CET
Created attachment 1354 [details]
re-diffed patch for ffmpeg-mp3_outlen (google)
Comment 11 David Walser 2012-01-09 17:40:49 CET
Created attachment 1355 [details]
re-diffed patch for ffmpeg-vorbis_zero_samplerate (google)
Comment 12 David Walser 2012-01-09 18:01:24 CET
Created attachment 1356 [details]
diff for the SPEC file
Comment 13 David Walser 2012-01-09 18:06:19 CET
All of these patches (as well as the ones from the previous Mageia 1 update, patches 36-42) should also be added to the Cauldron mplayer package.
Comment 14 David Walser 2012-01-10 01:58:34 CET
Advisory:
========================

Updated mplayer packages fix security vulnerabilities:

FFmpeg 0.5 allows remote attackers to cause a denial of service (hang)
via a crafted file that triggers an infinite loop. (CVE-2009-4636)

Fix heap corruption crashes (CVE-2011-0722)

And several additional vulnerabilites originally discovered by Google
Chrome developers were also fixed with this advisory.

References:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0722
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4636
http://www.mandriva.com/en/support/security/advisories/?dis=2010.1&name=MDVSA-2011:089
========================

Updated packages in core/updates_testing:
========================
mplayer-1.0-1.rc4.0.r32713.5.2.mga1
mplayer-doc-1.0-1.rc4.0.r32713.5.2.mga1
mplayer-gui-1.0-1.rc4.0.r32713.5.2.mga1
mencoder-1.0-1.rc4.0.r32713.5.2.mga1

from mplayer-1.0-1.rc4.0.r32713.5.2.mga1.src.rpm
Comment 15 David Walser 2012-01-10 02:48:43 CET
This is available for testing!

Assignee: bugsquad => qa-bugs

David Walser 2012-01-10 02:50:21 CET

Summary: mplayer missing security update for CVE-2009-4636, CVE-2010-3429, CVE-2010-4704, CVE-2011-0722 => mplayer missing security update for CVE-2009-4636 and CVE-2011-0722

Comment 16 Dave Hodgins 2012-01-10 17:56:36 CET
I thought the tainted versions would be automatically built at the same time,
but they are not showing up in the i586 Tainted Updates Testing repositories.

CC: (none) => davidwhodgins

Comment 17 David Walser 2012-01-10 18:53:35 CET
(In reply to comment #16)
> I thought the tainted versions would be automatically built at the same time,
> but they are not showing up in the i586 Tainted Updates Testing repositories.

I just checked the i586 tainted/updates_testing and it is there.
Comment 18 Dave Hodgins 2012-01-10 19:17:28 CET
Sorry, my mistake.  I'd disabled Tainted Updates Testing for a prior test,
and forget to re-enable it.  I'll try to remember to check the actual
repository in future.

Testing complete on i586 for the srpms
mplayer-1.0-1.rc4.0.r32713.5.2.mga1.src.rpm
mplayer-1.0-1.rc4.0.r32713.5.2.mga1.tainted.src.rpm

Played a variety of video and audio files, and used mencoder to
create a video from jpg images, then installed the tainted version
and played a .m4a file.
Comment 19 David GEIGER 2012-01-12 13:49:28 CET
Testing complete on Mageia release 1 (Official) for x86_64 for the srpms :
-mplayer-1.0-1.rc4.0.r32713.5.2.mga1.src.rpm
-mplayer-1.0-1.rc4.0.r32713.5.2.mga1.tainted.src.rpm

Works good for me too.

(In reply to comment #18)
>Played a variety of video and audio files, and used mencoder to
>create a video from jpg images, then installed the tainted version
>and played a .m4a file.

CC: (none) => geiger.david68210

Comment 20 David Walser 2012-01-12 15:06:11 CET
Validating.

Advisory in Comment 14.

Could sysadmin please push from core/updates_testing to core/updates

Thank you!

Keywords: (none) => validated_update
CC: (none) => sysadmin-bugs
Hardware: i586 => All

Comment 21 Thomas Backlund 2012-01-14 15:25:48 CET
update pushed for core and tainted

Status: NEW => RESOLVED
CC: (none) => tmb
Resolution: (none) => FIXED


Note You need to log in before you can comment on or make changes to this bug.