Bug 4154 - mplayer affected by new ffmpeg security issues
Summary: mplayer affected by new ffmpeg security issues
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 1
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact:
URL:
Whiteboard:
Keywords: validated_update
Depends on:
Blocks: 4146
  Show dependency treegraph
 
Reported: 2012-01-16 16:14 CET by David Walser
Modified: 2012-01-26 00:52 CET (History)
6 users (show)

See Also:
Source RPM: mplayer-1.0-1.rc4.0.r32713.5.2.mga1.src.rpm
CVE:
Status comment:


Attachments

Description David Walser 2012-01-16 16:14:56 CET
The advisory for ffmpeg is reported as Bug 4147.

There is also this advisory from Ubuntu which may be relevant:
http://bazaar.launchpad.net/~ubuntu-branches/ubuntu/maverick/ffmpeg/maverick-security/revision/54
David Walser 2012-01-16 16:15:26 CET

Blocks: (none) => 4146

Comment 1 Manuel Hiebel 2012-01-16 17:00:25 CET
Hi, thanks for reporting this bug.
As there is no maintainer for this package I added the committers in CC.

(Please set the status to 'assigned' if you are working on it)

CC: (none) => cjw, fundawang, mageia

Comment 2 David Walser 2012-01-16 22:51:14 CET
I bumped the subrel in Mageia 1 SVN and added the patches from the Ubuntu advisory, and they apply and build fine.

We still need patches for CVE-2011-3892, CVE-2011-3893, and CVE-2011-3895 from ffmpeg 0.6.5 to be identified and applied before this is built and pushed.
Comment 3 David Walser 2012-01-16 23:40:01 CET
OK I rediffed the patches listed as relevant to these CVEs from here:
http://git.videolan.org/?p=ffmpeg.git;a=log;h=refs/heads/release/0.6

and added them to Mageia 1 SVN.
Comment 4 David Walser 2012-01-19 03:44:44 CET
mplayer-1.0-1.rc4.0.r32713.5.3.mga1.src.rpm is built (including mplayer, mplayer-doc, mplayer-gui, and mencoder RPMs).  It is ready for testing!

Assignee: bugsquad => qa-bugs

Comment 5 Dave Hodgins 2012-01-21 05:38:37 CET
Testing complete on i586 for the srpms
mplayer-1.0-1.rc4.0.r32713.5.3.mga1.src.rpm
mplayer-1.0-1.rc4.0.r32713.5.3.mga1.tainted.src.rpm

Just testing that they work using gmplayer and lives, which uses mencoder
to resize all of the frames in a flash video, and then save each frame as
a png image.

CC: (none) => davidwhodgins

Comment 6 claire robinson 2012-01-23 19:36:55 CET
Tested OK x86_64

Used gnome-mplayer and some mencoder lines from http://networkedblogs.com/8Pgo
Confirmed tainted mencoder could encode with the xvidencopts line.


David, could you summarise the changes in an advisory please. 
This can then be validated.

Thankyou.
Comment 7 David Walser 2012-01-24 03:05:37 CET
Thanks Claire!  Validating.

Advisory:
========================

Updated mplayer packages fix security vulnerabilities:

* CVE-2011-3504: denial of service and possible code execution via
  malformed Matroska file

* CVE-2011-4351: denial of service and possible code execution via
  malformed file containing QDM2 stream

* CVE-2011-4352: denial of service and possible code execution via
  malformed file containing VP3 stream

* CVE-2011-4353: denial of service and possible code execution via
  malformed file containing VP5 or VP6 streams

* CVE-2011-4364: denial of service and possible code execution via
  malformed VMD file

* CVE-2011-4579: denial of service and possible code execution via
  malformed file containing svq1 stream

* CVE-2011-3892: denial of service via malformed stream for the VP3 decoder

* CVE-2011-3893, CVE-2011-3895: denial of service and possible code execution via malformed stream for the vorbis decoder and matroska demuxer

References:
http://bazaar.launchpad.net/~ubuntu-branches/ubuntu/maverick/ffmpeg/maverick-security/revision/54
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3892
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3893
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3895
========================

Updated packages in core/updates_testing:
========================
mencoder-1.0-1.rc4.0.r32713.5.3.mga1
mplayer-1.0-1.rc4.0.r32713.5.3.mga1
mplayer-doc-1.0-1.rc4.0.r32713.5.3.mga1
mplayer-gui-1.0-1.rc4.0.r32713.5.3.mga1

from mplayer-1.0-1.rc4.0.r32713.5.3.mga1.src.rpm
========================

Could sysadmin please push from core/updates_testing to core/updates

Thank you!

Keywords: (none) => validated_update
CC: (none) => sysadmin-bugs
Hardware: i586 => All

Comment 8 Thomas Backlund 2012-01-25 12:58:15 CET
update pushed

Status: NEW => RESOLVED
CC: (none) => tmb
Resolution: (none) => FIXED

Comment 9 Thomas Backlund 2012-01-26 00:52:44 CET
Gah, comment #7 missed to point out the mplayer in tainted, so it was not pushed,
and we got this: https://bugs.mageia.org/show_bug.cgi?id=4284

I have now pushed the tainted update.

Note You need to log in before you can comment on or make changes to this bug.