Alsaplayer crashes

Bug #117395 reported by Jarno Suni
262
Affects Status Importance Assigned to Milestone
alsaplayer (Ubuntu)
New
Undecided
Unassigned
Nominated for Jaunty by pranith

Bug Description

Happens in Dapper, alsaplayer 0.99.76.

Steps to reproduce:
1) Launch alsaplayer
2) Click on CD Player (CDDA) on the leftmost menu.

CVE References

Revision history for this message
Brian Murray (brian-murray) wrote :

Thanks for taking the time to report this bug and helping to make Ubuntu better. This bug did not have a package associated with it, which is important for ensuring that it gets looked at by the proper developers. You can learn more about finding the right package at https://wiki.ubuntu.com/Bugs/FindRightPackage . I have classified this bug as a bug in alsaplayer.

Revision history for this message
Dominique (dominique-michel) wrote :

0.99.76 is outdated and have several critical security bugs. Please update to the last version. You will get a gtk2 interface for the same price.

Dominique Michel, AlsaPlayer administrator.

Revision history for this message
Jouni Mettala (jouni-mettala) wrote :

CVE-2007-5301

Revision history for this message
Dominique (dominique-michel) wrote : Re: [Bug 117395] Re: Alsaplayer crashes

Le Mon, 17 Dec 2007 18:41:36 -0000,
Jouni Mettala <email address hidden> a écrit :

> CVE-2007-5301
>
> ** CVE added: http://www.cve.mitre.org/cgi-
> bin/cvename.cgi?name=2007-5301
>
> ** This bug has been flagged as a security issue
>

If you follow the links in CVE's repport, you will find this:
http://secunia.com/advisories/27117
quote:
Solution:
The vendor has released 0.99.80-rc3, which fixes the vulnerabilities.
Endquote

Please, update to 0.99.80-rc3, or better to 0.99.80.

Cheers,
--
Dominique Michel

Mes 3 projets préférés auxquels je contribue:
 * FVWM-Crystal, le bureau basé sur FVWM:
      http://fvwm-crystal.org
 * AlsaPlayer, le lecteur audio avec contrôle de vitesse en continu:
      www.alsaplayer.org
 * L'overlay pour la MAO sous gentoo:
      http://proaudio.tuxfamily.org/wiki/index.php?title=Main_Page

Revision history for this message
Dominique (dominique-michel) wrote :

The buig in the vorbis plugin is fixed in 0.99.80-rc3 by Erik Sjölund. See http://secunia.com/advisories/27117 and the 2 first links (to sourceforge) in CVE repport. BTW, 0.99.80 is out.

Revision history for this message
pranith (bobby-prani) wrote :

I think this is fixed for now. nominating it for release

To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.