[SECURITY] Fedora 8 Update: xine-lib-1.1.15-1.fc8

updates at fedoraproject.org updates at fedoraproject.org
Wed Sep 10 06:45:50 UTC 2008


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2008-7572
2008-09-05 10:52:57
--------------------------------------------------------------------------------

Name        : xine-lib
Product     : Fedora 8
Version     : 1.1.15
Release     : 1.fc8
URL         : http://xinehq.de/
Summary     : Xine library
Description :
This package contains the Xine library. Xine is a free multimedia player.
It can play back various media. It also decodes multimedia files from local
disk drives, and displays multimedia streamed over the Internet. It
interprets many of the most common multimedia formats available - and some
of the most uncommon formats, too.  --with/--without rpmbuild options
(some default values depend on target distribution): aalib, caca, directfb,
imagemagick, freetype, antialiasing (with freetype), pulseaudio, xcb.

--------------------------------------------------------------------------------
Update Information:

This release fixes multiple bugs and security issues:  - DoS via corrupted Ogg
files (CVE-2008-3231)  - multiple possible buffer overflows detailed in
oCERT-2008-008    For more details, see:
http://sourceforge.net/project/shownotes.php?release_id=619869&group_id=9655
http://www.ocert.org/advisories/ocert-2008-008.html    NOTE: A coordinated
release with 3rd-party repos was not possible, so this update may result in
dependency issues with currently-installed xine-lib-extras-* rpms.  This
temporary problem will be rectified asap.
--------------------------------------------------------------------------------
ChangeLog:

* Wed Aug 20 2008 Rex Dieter <rdieter at fedoraproject.org> - 1.1.15-1
- xine-lib-1.1.15, plugin ABI 1.24 (rh#455752, CVE-2008-3231)
- Obsoletes: -arts (f9+)
* Sun Apr 27 2008 Kevin Kofler <Kevin at tigcc.ticalc.org> - 1.1.12-3
- rebuild for new ImageMagick (6.4.0.10)
* Thu Apr 24 2008 Rex Dieter <rdieter at fedoraproject.org> - 1.1.12-2
- CVE-2008-1878
* Wed Apr 16 2008 Ville Skyttä <ville.skytta at iki.fi> - 1.1.12-1
- 1.1.12 (plugin ABI 1.21); qt, mkv, and pulseaudio patches applied upstream.
* Wed Apr  9 2008 Ville Skyttä <ville.skytta at iki.fi> - 1.1.11.1-3
- Apply upstream fixes for Quicktime (#441705) and Matroska regressions
  introduced in 1.1.11.1.
* Mon Apr  7 2008 Rex Dieter <rdieter at fedoraproject.org> - 1.1.11.1-2
- pulse-rework2 patch (#439731)
- -pulseaudio subpkg (#439731)
* Sun Mar 30 2008 Ville Skyttä <ville.skytta at iki.fi> - 1.1.11.1-1
- 1.1.11.1 (security update, #438663, CVE-2008-1482).
- Provide versioned xine-lib(plugin-abi) so 3rd party packages installing
  plugins can use it instead of requiring a version of xine-lib.
* Wed Mar 19 2008 Ville Skyttä <ville.skytta at iki.fi> - 1.1.11-1
- 1.1.11 (security update, #438182, CVE-2008-0073).
- Drop jack and wavpack build conditionals.
- Specfile cleanups.
* Fri Mar  7 2008 Rex Dieter <rdieter at fedoraproject.org> - 1.1.10.1-1.1
- xcb support for f7+ (#373411)
* Fri Feb  8 2008 Ville Skyttä <ville.skytta at iki.fi> - 1.1.10.1-1
- 1.1.10.1 (security update, #431541).
* Sun Jan 27 2008 Ville Skyttä <ville.skytta at iki.fi> - 1.1.10-2
- Include spu, spucc, and spucmml decoders (#213597).
* Sun Jan 27 2008 Ville Skyttä <ville.skytta at iki.fi> - 1.1.10-1
- 1.1.10 (security update).
* Mon Jan 21 2008 Ville Skyttä <ville.skytta at iki.fi> - 1.1.9.1-3
- Fix version number in libxine.pc (#429487).
* Sun Jan 20 2008 Ville Skyttä <ville.skytta at iki.fi> - 1.1.9.1-2
- Disable upstream "discard buffers on ao close" 1.1.9 changeset (#429182).
* Sat Jan 12 2008 Ville Skyttä <ville.skytta at iki.fi> - 1.1.9.1-1
- 1.1.9.1 (security update).
* Sun Jan  6 2008 Ville Skyttä <ville.skytta at iki.fi> - 1.1.9-1
- 1.1.9.
* Thu Sep 27 2007 Ville Skyttä <ville.skytta at iki.fi> - 1.1.8-6
- Enable wavpack support by default for all distros.
* Sun Sep 23 2007 Ville Skyttä <ville.skytta at iki.fi> - 1.1.8-5
- Enable JACK support by default for all distros.
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #456057 - CVE-2008-3231 xine-lib: crash on zzuf test case lol-ffplay.ogg
        https://bugzilla.redhat.com/show_bug.cgi?id=456057
--------------------------------------------------------------------------------

This update can be installed with the "yum" update program.  Use 
su -c 'yum update xine-lib' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.

All packages are signed with the Fedora Project GPG key.  More details on the
GPG keys used by the Fedora Project can be found at
http://fedoraproject.org/keys
--------------------------------------------------------------------------------




More information about the Fedora-package-announce mailing list