[Bug 2033955] [NEW] [SRU] New upstream bugfix releases 4.2.9, 4.4.4 and 5.1.3

Launchpad Bug Tracker 2033955 at bugs.launchpad.net
Wed Sep 6 13:45:43 UTC 2023


*** This bug is a security vulnerability ***

You have been subscribed to a public security bug by Luís Infante da Câmara (luis220413):

[Impact]

New upstream bugfix releases 4.2.9, 4.4.4 and 5.1.3 are available.

These releases fix:
* CVE-2022-48434 in Ubuntu 22.04 and
* CVE-2022-3964, CVE-2022-3965 and CVE-2022-4907 in Ubuntu 23.04 and
* many other bugs.

[Test Plan]

For each Ubuntu release being updated and each architecture of amd64, arm64, and other architectures that can be tested, run the following commands in a chroot, container or VM of that Ubuntu release and architecture:
[Download the .dsc file for the update]
$ sudo apt install build-essential
$ dpkg-source -x $SOURCE_DSC
$ cd ffmpeg-$UPSTREAM_VERSION
$ debuild -us -uc
[If required, install build dependencies and repeat the command]
$ export LD_LIBRARY_PATH="libavcodec:libavdevice:libavfilter:libavformat:libavresample:libavutil:libpostproc:libswresample:libswscale"
$ cd debian/standard
$ make fate-rsync SAMPLES=fate-suite/
$ make fate -k SAMPLES=fate-suite/

[Where problems could occur]

The bug fixes in this update could create regressions in other packages
in the Ubuntu archive or in third-party software.

** Affects: ffmpeg (Ubuntu)
     Importance: Undecided
         Status: Fix Released


** Tags: community-security focal jammy lunar
-- 
[SRU] New upstream bugfix releases 4.2.9, 4.4.4 and 5.1.3
https://bugs.launchpad.net/bugs/2033955
You received this bug notification because you are a member of Ubuntu Sponsors, which is subscribed to the bug report.



More information about the Ubuntu-sponsors mailing list