[ubuntu/intrepid] mplayer 2:1.0~rc2-0ubuntu17 (Accepted)

Stefan Lesicnik stefan at lsd.co.za
Wed Oct 8 11:00:11 BST 2008


mplayer (2:1.0~rc2-0ubuntu17) intrepid; urgency=low

  * SECURITY UPDATE: Multiple integer underflows in MPlayer 1.0_rc2 and
    earlier allow remote attackers to cause a denial of service
    (process termination) and possibly execute arbitrary code via a
    crafted video file that causes the stream_read function to read or
    write arbitrary memory. (LP: #279030)
    - libmpdemux/demux_real.c - patch from oCert.
    - References:
      + CVE-2008-3827
      + http://www.ocert.org/advisories/ocert-2008-013.html

Date: Wed, 08 Oct 2008 07:51:18 +0200
Changed-By: Stefan Lesicnik <stefan at lsd.co.za>
Maintainer: Ubuntu MOTU Media Team <motumedia at tauware.de>
Signed-By: William Grant <william at qeuni.net>
https://launchpad.net/ubuntu/intrepid/+source/mplayer/2:1.0~rc2-0ubuntu17
-------------- next part --------------
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Format: 1.8
Date: Wed, 08 Oct 2008 07:51:18 +0200
Source: mplayer
Binary: mplayer mplayer-nogui mencoder mplayer-doc
Architecture: source
Version: 2:1.0~rc2-0ubuntu17
Distribution: intrepid
Urgency: low
Maintainer: Ubuntu MOTU Media Team <motumedia at tauware.de>
Changed-By: Stefan Lesicnik <stefan at lsd.co.za>
Description: 
 mencoder   - MPlayer's Movie Encoder
 mplayer    - The Ultimate Movie Player For Linux
 mplayer-doc - The Ultimate Movie Player For Linux (Documentation)
 mplayer-nogui - The Ultimate Movie Player For Linux
Launchpad-Bugs-Fixed: 279030
Changes: 
 mplayer (2:1.0~rc2-0ubuntu17) intrepid; urgency=low
 .
   * SECURITY UPDATE: Multiple integer underflows in MPlayer 1.0_rc2 and
     earlier allow remote attackers to cause a denial of service
     (process termination) and possibly execute arbitrary code via a
     crafted video file that causes the stream_read function to read or
     write arbitrary memory. (LP: #279030)
     - libmpdemux/demux_real.c - patch from oCert.
     - References:
       + CVE-2008-3827
       + http://www.ocert.org/advisories/ocert-2008-013.html
Checksums-Sha1: 
 c7733f9072ed54a6ff387452c8da73fa3e5ced25 2079 mplayer_1.0~rc2-0ubuntu17.dsc
 e85955e218a5077af4dbcf13cd7193d5a51f5003 20917 mplayer_1.0~rc2-0ubuntu17.diff.gz
Checksums-Sha256: 
 97fa71fa84d149cfaa054c7caeb850deee2691acb820947856d5c1e8a51372bc 2079 mplayer_1.0~rc2-0ubuntu17.dsc
 1db194cc88eb0fddecc31088ccbc017dcd128f7fd09d73762a6e97164aa21696 20917 mplayer_1.0~rc2-0ubuntu17.diff.gz
Files: 
 7d16e19bb7798a335c2f339535670bc3 2079 graphics extra mplayer_1.0~rc2-0ubuntu17.dsc
 2936eec31e47957cc69369170fcdc23f 20917 graphics extra mplayer_1.0~rc2-0ubuntu17.diff.gz

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.9 (GNU/Linux)

iEYEARECAAYFAkjsg0oACgkQAc+S8KckfcXFUACeIKl/weyQVAXzM00TCHHYSzsn
K2oAnjTihi6KVZoMTRgyptGaEDE9O/MB
=d7rU
-----END PGP SIGNATURE-----


More information about the Intrepid-changes mailing list