blob: 69cc41066c40197a6e73e82f9a30f3a446cd16e3 (
plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
|
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 3.2//EN">
<HTML>
<HEAD>
<TITLE> [Mageia-dev] taglib CVE for MP4 files
</TITLE>
<LINK REL="Index" HREF="index.html" >
<LINK REL="made" HREF="mailto:mageia-dev%40mageia.org?Subject=Re%3A%20%5BMageia-dev%5D%20taglib%20CVE%20for%20MP4%20files&In-Reply-To=%3C20120514222127.3f49c08e%40lap.shlomifish.org%3E">
<META NAME="robots" CONTENT="index,nofollow">
<META http-equiv="Content-Type" content="text/html; charset=us-ascii">
<LINK REL="Previous" HREF="015648.html">
<LINK REL="Next" HREF="015649.html">
</HEAD>
<BODY BGCOLOR="#ffffff">
<H1>[Mageia-dev] taglib CVE for MP4 files</H1>
<B>Shlomi Fish</B>
<A HREF="mailto:mageia-dev%40mageia.org?Subject=Re%3A%20%5BMageia-dev%5D%20taglib%20CVE%20for%20MP4%20files&In-Reply-To=%3C20120514222127.3f49c08e%40lap.shlomifish.org%3E"
TITLE="[Mageia-dev] taglib CVE for MP4 files">shlomif at shlomifish.org
</A><BR>
<I>Mon May 14 21:21:27 CEST 2012</I>
<P><UL>
<LI>Previous message: <A HREF="015648.html">[Mageia-dev] taglib CVE for MP4 files
</A></li>
<LI>Next message: <A HREF="015649.html">[Mageia-dev] sysadmin please remove tuxguitar-1.2-7.1.mga1
</A></li>
<LI> <B>Messages sorted by:</B>
<a href="date.html#15651">[ date ]</a>
<a href="thread.html#15651">[ thread ]</a>
<a href="subject.html#15651">[ subject ]</a>
<a href="author.html#15651">[ author ]</a>
</LI>
</UL>
<HR>
<!--beginarticle-->
<PRE>Hi David,
On Mon, 14 May 2012 11:43:46 -0700 (PDT)
David Walser <<A HREF="https://www.mageia.org/mailman/listinfo/mageia-dev">luigiwalser at yahoo.com</A>> wrote:
><i> taglib 1.7.2 was issued to fix a minor security DoS issue due to a divide by zero error in the MP4 file decoder.
</I>><i>
</I>><i> I built it in updates_testing but I don't have an MP4 file to test it with.
</I>><i>
</I>><i> If interested people could test it, it could be pushed to updates. Thanks.
</I>><i>
</I>
Thanks for your work. I have some .mp4s files (mostly videos) around, which I
have downloaded from YouTube using youtube-dl (and you can too). But what
should I do to test that the bug was fixed? Can you provide instructions?
Regards,
Shlomi Fish
--
-----------------------------------------------------------------
Shlomi Fish <A HREF="http://www.shlomifish.org/">http://www.shlomifish.org/</A>
Understand what Open Source is - <A HREF="http://shlom.in/oss-fs">http://shlom.in/oss-fs</A>
Tcl is Lisp on drugs. Using strings instead of S‐expressions for closures is
Evil with one of those gigantic E’s you can find at the beginning of chapters.
Please reply to list if it's a mailing list post - <A HREF="http://shlom.in/reply">http://shlom.in/reply</A> .
</PRE>
<!--endarticle-->
<HR>
<P><UL>
<!--threads-->
<LI>Previous message: <A HREF="015648.html">[Mageia-dev] taglib CVE for MP4 files
</A></li>
<LI>Next message: <A HREF="015649.html">[Mageia-dev] sysadmin please remove tuxguitar-1.2-7.1.mga1
</A></li>
<LI> <B>Messages sorted by:</B>
<a href="date.html#15651">[ date ]</a>
<a href="thread.html#15651">[ thread ]</a>
<a href="subject.html#15651">[ subject ]</a>
<a href="author.html#15651">[ author ]</a>
</LI>
</UL>
<hr>
<a href="https://www.mageia.org/mailman/listinfo/mageia-dev">More information about the Mageia-dev
mailing list</a><br>
</body></html>
|