[Bug 2033955] Re: [SRU] New upstream bugfix releases 4.2.9, 4.4.4 and 5.1.3

Luís Infante da Câmara 2033955 at bugs.launchpad.net
Wed Sep 6 13:45:03 UTC 2023


** Patch added: "ffmpeg_lunar.debdiff"
   https://bugs.launchpad.net/ubuntu/+source/ffmpeg/+bug/2033955/+attachment/5697991/+files/ffmpeg_lunar.debdiff

** Changed in: ffmpeg (Ubuntu)
       Status: Incomplete => New

** Changed in: ffmpeg (Ubuntu)
       Status: New => Fix Released

** Information type changed from Public Security to Public

-- 
You received this bug notification because you are a member of Ubuntu
Sponsors, which is subscribed to the bug report.
https://bugs.launchpad.net/bugs/2033955

Title:
  [SRU] New upstream bugfix releases 4.2.9, 4.4.4 and 5.1.3

Status in ffmpeg package in Ubuntu:
  Fix Released

Bug description:
  [Impact]

  New upstream bugfix releases 4.2.9, 4.4.4 and 5.1.3 are available.

  These releases fix:
  * CVE-2022-48434 in Ubuntu 22.04 and
  * CVE-2022-3964, CVE-2022-3965 and CVE-2022-4907 in Ubuntu 23.04 and
  * many other bugs.

  [Test Plan]

  For each Ubuntu release being updated and each architecture of amd64, arm64, and other architectures that can be tested, run the following commands in a chroot, container or VM of that Ubuntu release and architecture:
  [Download the .dsc file for the update]
  $ sudo apt install build-essential
  $ dpkg-source -x $SOURCE_DSC
  $ cd ffmpeg-$UPSTREAM_VERSION
  $ debuild -us -uc
  [If required, install build dependencies and repeat the command]
  $ export LD_LIBRARY_PATH="libavcodec:libavdevice:libavfilter:libavformat:libavresample:libavutil:libpostproc:libswresample:libswscale"
  $ cd debian/standard
  $ make fate-rsync SAMPLES=fate-suite/
  $ make fate -k SAMPLES=fate-suite/

  [Where problems could occur]

  The bug fixes in this update could create regressions in other
  packages in the Ubuntu archive or in third-party software.

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/ffmpeg/+bug/2033955/+subscriptions




More information about the Ubuntu-sponsors mailing list