Please do not reply directly to this email. All additional comments should be made in the comments box of this bug report.
https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=231734
Summary: CVE-2007-1246: xine-lib buffer overflow Product: Fedora Extras Version: fc5 Platform: All OS/Version: Linux Status: NEW Severity: normal Priority: normal Component: xine-lib AssignedTo: gauret@free.fr ReportedBy: ville.skytta@iki.fi QAContact: extras-qa@fedoraproject.org CC: fedora-security-list@redhat.com,ville.skytta@iki.fi
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2007-1246
Originally reported against MPlayer, but it turns out xine-lib is vulnerable too. Upstream fix pushed to FC6+ (1.1.4-3 currently building), but FC5 is still at 1.1.2, probably already lacking "several bug and security fixes" as put by upstream in the 1.1.3 release announcement. No FC5 system here to test with, so leaving up to Aurelien to decide whether to update while at it or just to possibly apply the patch for this issue from FC6+ (if it applies, unchecked).
------- Additional Comments From ville.skytta@iki.fi 2007-03-10 17:29 EST ------- Created an attachment (id=149781) --> (https://bugzilla.redhat.com/bugzilla/attachment.cgi?id=149781&action=vie...) Fix from upstream CVS
Please do not reply directly to this email. All additional comments should be made in the comments box of this bug report.
Summary: CVE-2007-1246, CVE-2007-1387: xine-lib buffer overflows
https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=231734
ville.skytta@iki.fi changed:
What |Removed |Added ---------------------------------------------------------------------------- Summary|CVE-2007-1246: xine-lib |CVE-2007-1246, CVE-2007- |buffer overflow |1387: xine-lib buffer | |overflows
------- Additional Comments From ville.skytta@iki.fi 2007-03-14 10:35 EST ------- Patch in comment 1 fixes CVE-2007-1387 too.
Please do not reply directly to this email. All additional comments should be made in the comments box of this bug report.
Summary: CVE-2007-1246, CVE-2007-1387: xine-lib buffer overflows
https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=231734
bugzilla@redhat.com changed:
What |Removed |Added ---------------------------------------------------------------------------- Severity|normal |medium Priority|normal |medium
gauret@free.fr changed:
What |Removed |Added ---------------------------------------------------------------------------- Status|NEW |CLOSED Resolution| |CURRENTRELEASE Fixed In Version| |1.1.7
security@lists.fedoraproject.org