Sync libvorbis 1.2.0.dfsg-6 (main) from Debian unstable (main).

Bug #413528 reported by Michael Bienia
8
This bug affects 1 person
Affects Status Importance Assigned to Milestone
libvorbis (Ubuntu)
Fix Released
Wishlist
Unassigned

Bug Description

Please sync libvorbis 1.2.0.dfsg-6 (main) from Debian unstable (main).

Changelog since current karmic version 1.2.0.dfsg-5:

libvorbis (1.2.0.dfsg-6) unstable; urgency=high

  * Fix CVE-2009-2663: two bugs in libvorbis that allowed a crafted ogg
    file to corrupt memory. (Closes: #540958)
  * patches/CVE-2008-1420.patch: fix a regression playing files generated
    by 1.0b1, from upstream trunk. Thanks Michael Gold. (Closes: #504421)

 -- Peter Samuelson <email address hidden> Mon, 10 Aug 2009 23:11:11 -0500

Michael Bienia (geser)
Changed in libvorbis (Ubuntu):
importance: Undecided → Wishlist
Revision history for this message
Daniel Holbach (dholbach) wrote :

ACKed.

Changed in libvorbis (Ubuntu):
status: New → Confirmed
Revision history for this message
James Westby (james-w) wrote :

[Updating] libvorbis (1.2.0.dfsg-5 [Ubuntu] < 1.2.0.dfsg-6 [Debian])
 * Trying to add libvorbis...
  - <libvorbis_1.2.0.dfsg-6.diff.gz: downloading from http://ftp.debian.org/debian/>
  - <libvorbis_1.2.0.dfsg-6.dsc: downloading from http://ftp.debian.org/debian/>
  - <libvorbis_1.2.0.dfsg.orig.tar.gz: already in distro - downloading from librarian>
I: libvorbis [main] -> libvorbis0a_1.2.0.dfsg-5 [main].
I: libvorbis [main] -> libvorbisenc2_1.2.0.dfsg-5 [main].
I: libvorbis [main] -> libvorbisfile3_1.2.0.dfsg-5 [main].
I: libvorbis [main] -> libvorbis-dev_1.2.0.dfsg-5 [main].

Changed in libvorbis (Ubuntu):
status: Confirmed → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.