update swfdec to 0.6.4 version (local file access via remote flash file)

Bug #214905 reported by Roberto Cássio Jr.
266
Affects Status Importance Assigned to Milestone
swfdec-mozilla (Ubuntu)
Invalid
Undecided
Unassigned
swfdec0.6 (Ubuntu)
Fix Released
Wishlist
Unassigned

Bug Description

Binary package hint: swfdec-mozilla

New version is a bugfix release which solves a very important security issue. Here goes the announcement, according to http://lists.freedesktop.org/archives/swfdec/2008-April/001321.html :

==============================================
Here's the release of Swfdec 0.6.4.

This is a security release, please update as soon as possible.

swfdec-0.6.4 "College Humor"
http://swfdec.freedesktop.org/download/swfdec/0.6/swfdec-0.6.4.tar.gz
MD5: a1568696246889109b884cb5434e81fc

fixes in this release:
- fix a security problem that allowed remote Flash files to read local files.
- fix a rare crash in TextField.replaceText
- fix a rare crash during cleanup

Swfdec still follows the no-crashes-allowed policy. Should you still
succeed in finding a crasher, please immediately file a bug at
https://bugs.freedesktop.org.

For more information about Swfdec, see http://swfdec.freedesktop.org

Cheers,
Benjamin
==============================================

I don't know, since it's a minor release with bug fixes, if a feature freeze break is needed. If needed, someone please do the necessary process, because I don't know yet to use the tools to provide everything needed for the break.

Revision history for this message
Stéphane Loeuillet (leroutier) wrote :

Only swfdec core is impacted (and has been updated)
swfdec-mozilla stays at v0.6.0

Changed in swfdec-mozilla:
status: New → Invalid
Changed in swfdec0.6:
status: New → Confirmed
Revision history for this message
Sebastien Bacher (seb128) wrote :

the new version has been synced in hardy now

Changed in swfdec0.6:
importance: Undecided → Wishlist
status: Confirmed → Fix Released
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Duplicates of this bug

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.