Resync ffmpeg with ubuntu

Bug #343905 reported by Lionel Le Folgoc
6
Affects Status Importance Assigned to Milestone
Medibuntu
Invalid
Undecided
Unassigned
Gutsy
Fix Released
Medium
Lionel Le Folgoc
Hardy
Fix Released
Medium
Lionel Le Folgoc

Bug Description

https://launchpad.net/ubuntu/+source/ffmpeg/3:0.cvs20070307-5ubuntu4.2

ffmpeg (3:0.cvs20070307-5ubuntu4.2) gutsy-security; urgency=low

  * SECURITY UPDATE: denial of service via a malformed Ogg Media (OGM) file
    - debian/patches/100_security_CVE-2008-4610.diff: properly check return
      codes in libavcodec/vp3.c.
    - CVE-2008-4610
  * SECURITY UPDATE: buffer overflow caused by an incorrect DCA_MAX_FRAME_SIZE
    value
    - debian/patches/101_security_CVE-2008-4867.diff: set DCA_MAX_FRAME_SIZE to
      a correct value in libavcodec/dca.c.
    - CVE-2008-4867
  * SECURITY UPDATE: arbitrary code execution via a malformed 4X movie file
    (LP: #323620)
    - debian/patches/102_security_CVE-2009-0385.diff: validate current_track
      value in libavformat/4xm.c.
    - CVE-2009-0385

Revision history for this message
Lionel Le Folgoc (mrpouit) wrote :

Only gutsy is affected.

Changed in medibuntu:
status: New → Invalid
Revision history for this message
Lionel Le Folgoc (mrpouit) wrote :
Revision history for this message
Andy Balaam (mail-artificialworlds) wrote :

I am seeing this on Hardy, which I guess is the same problem?:

$ cat /etc/lsb-release
DISTRIB_ID=Ubuntu
DISTRIB_RELEASE=8.04
DISTRIB_CODENAME=hardy
DISTRIB_DESCRIPTION="Ubuntu 8.04.2"

$ ffmpeg -re -r 25 -y -i "input.ts" -b 900k -async 1000 -ar 44100 -s 566x330 -f flv -ar 22050 -acodec mp3 "output.flv"
FFmpeg version SVN-rUNKNOWN, Copyright (c) 2000-2007 Fabrice Bellard, et al.
  configuration: --enable-gpl --enable-pp --enable-swscaler --enable-pthreads --enable-libvorbis --enable-libtheora --enable-libogg --enable-libgsm --enable-dc1394 --disable-debug --enable-shared --prefix=/usr
  libavutil version: 1d.49.3.0
  libavcodec version: 1d.51.38.0
  libavformat version: 1d.51.10.0
  built on Mar 16 2009 21:16:26, gcc: 4.2.4 (Ubuntu 4.2.4-1ubuntu3)
Input #0, mpegts, from '/home/andy/Videos/Recorded/Mister_Maker-2009-03-17_15_05.ts':
  Duration: 00:29:59.5, start: 85619.693600, bitrate: 4739 kb/s
  Stream #0.0[0x258]: Video: mpeg2video, yuv420p, 720x576, 4350 kb/s, 25.00 fps(r)
  Stream #0.1[0x259]: Audio: mp2, 48000 Hz, stereo, 256 kb/s
Output #0, flv, to '/home/andy/Videos/Wii/kids/Mister_Maker/2009-03-17_15_05_00_BBC_ONE_before_flvtool2.flv':
  Stream #0.0: Video: flv, yuv420p, 566x330, q=2-31, 900 kb/s, 25.00 fps(c)
  Stream #0.1: Audio: 0x0000, 22050 Hz, stereo, 64 kb/s
Stream mapping:
  Stream #0.0 -> #0.0
  Stream #0.1 -> #0.1
Unsupported codec for output stream #0.1
Error: ffmpeg returned '1'

Revision history for this message
MLSoft (mlsoft) wrote :

the Hardy version just bumped from ubuntu-7.1 to ubuntu-7.3 and the medibuntu-one is ubuntu-7.1+medibuntu?

should jump the version to ubuntu7.3+medibuntu?

resyncing with ubuntu, seems needed for hardy to keep working,
I just marked the 7.3 from ubuntu as Forbidden, but i do not like the side effects.

Revision history for this message
Lionel Le Folgoc (mrpouit) wrote :

Yes, there is an hardy task open as well...

> I just marked the 7.3 from ubuntu as Forbidden, but i do not like the side effects.

Yes, please don't do that (when Ubuntu releases a security fix) unless you are playing media files from trusted sources only...

Revision history for this message
Lionel Le Folgoc (mrpouit) wrote :

[gutsy] uploaded for i386/amd64/source (TODO: powerpc/sparc)

Revision history for this message
Lionel Le Folgoc (mrpouit) wrote :

[hardy] uploaded for i386/amd64/lpia/source (TODO: powerpc)

Revision history for this message
MLSoft (mlsoft) wrote : Re: [Bug 343905] Re: Resync ffmpeg with ubuntu

On Tuesday 17 March 2009 17:34:28 Lionel Le Folgoc wrote:
> [hardy] uploaded for i386/amd64/lpia/source (TODO: powerpc)
>
> ** Changed in: medibuntu/hardy
> Status: In Progress => Fix Committed
>

Wow, the fix is fast!!!

THANKS !!!

--
Martin Laberge
<email address hidden>
Tel:(418)521-6823
30 Years of Unix Admin, and still learning...

Revision history for this message
Andy Balaam (mail-artificialworlds) wrote :

Great, thanks - now works for me.

Revision history for this message
Lionel Le Folgoc (mrpouit) wrote :

Uploaded as well for powerpc and sparc, sorry for the delay.

To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.