[UVF Exception] Sync mpg123 (0.60-3) from Debian unstable (main)

Bug #64924 reported by Michael Bienia
6
Affects Status Importance Assigned to Milestone
mpg123 (Ubuntu)
Fix Released
Medium
Scott James Remnant (Canonical)

Bug Description

Reason:

According to the Debian changelog this fixes CVE-2006-3355 and CVE-2006-1655.
http://packages.debian.org/changelogs/pool/main/m/mpg123/current/changelog

CVE References

Revision history for this message
Michael Bienia (geser) wrote :
Revision history for this message
Michael Bienia (geser) wrote :

New entries from ChangeLog (the format of the ChangeLog has changed between version).

Revision history for this message
Michael Bienia (geser) wrote :

The same for NEWS

Michael Bienia (geser)
Changed in mpg123:
assignee: nobody → motu-uvf
Revision history for this message
Dave Sullivan (dsullivan) wrote :

Here's a buildlog for mpg123 0.60-3 i386.

Revision history for this message
Daniel Holbach (dholbach) wrote :

Security fix, please go ahead.

Changed in mpg123:
status: Unconfirmed → Confirmed
assignee: motu-uvf → geser
importance: Undecided → Medium
Revision history for this message
Michael Bienia (geser) wrote :

Please sync mpg123 (0.60-3) from Debian unstable (main).

The Ubuntu package has no changes.

The package builds clean in an edgy pbuilder.

Thanks.

Changelog:

 mpg123 (0.60-3) unstable; urgency=low

   * debian/rules: When generating $pkgname.mime, don't point to master
     file but copy over its contents. Closes: #390450

 -- Daniel Kobras <email address hidden> Sun, 1 Oct 2006 17:21:19 +0200

 mpg123 (0.60-2) unstable; urgency=low

   * debian/rules: Pass per-arch list of built packages to debhelper calls.
     Fixes build failures on architectures that build only a subset of all
     packages. Closes: #390077

 -- Daniel Kobras <email address hidden> Fri, 29 Sep 2006 11:04:42 +0200

 mpg123 (0.60-1) unstable; urgency=low

   * New upstream release.
     + Includes security fix for a heap overflow in httpget.c
       (CVE-2006-3355). Closes: #377264
   * configure, configure.ac: Fix typo to make esd detection work.
   * src/audio_esd.c: Always define audio_queueflush().
   * debian/compat: Set to debhelper compatibility level 5.
   * debian/control: Move from non-free to main. Closes: #292260
   * debian/control: OSS versions depend on oss-compat now.
   * debian/control: Build-depend on pkg-config. Configure script uses it.
   * debian/control: Build-depend on dephelper and autotools-dev.
   * debian/copyright: Download location now points to SourceForge site.
   * debian/copyright: Document new copyright and license, and add pointer to
     documentation of relicensing process.
   * debian/mime: Require a terminal when called via mailcap.
   * debian/rules: Debhelperize.
   * debian/rules: Tweak rules for new configure-style build system.
   * debian/rules: Add magic touches to prevent accidential rebuiling of
     configure.
   * debian/{control,rules}: Reinstate mpg123-alsa package now that current
     ALSA versions are supported again.

 -- Daniel Kobras <email address hidden> Thu, 14 Sep 2006 13:49:03 +0200

 mpg123 (0.59r-22) unstable; urgency=high

   * layer3.c: Fix buffer overflow in III_i_stereo() (CVE-2006-1655).
     Closes: #361863
   * mpg123.1: Fix several typos in man page. Patch thanks to A Costa.
     Closes: #350356
   * decode_i386.c: Cheat around strict aliasing problem in WRITE_SAMPLE().
   * Makefile: Replace deprecated -mcpu option with -mtune in x86 targets.
   * debian/control: Complies with version 3.6.2 of Debian policy. Bump
     Standards-Version accordingly.

 -- Daniel Kobras <email address hidden> Fri, 28 Apr 2006 18:27:35 +0200

Changed in mpg123:
assignee: geser → nobody
Revision history for this message
Scott James Remnant (Canonical) (canonical-scott) wrote :

[Updating] mpg123 (0.59r-21 [Ubuntu] < 0.60-3 [Debian])
 * Trying to add mpg123...
  - <mpg123_0.60-3.dsc: downloading from http://ftp.uk.debian.org/debian/>
  - <mpg123_0.60-3.diff.gz: downloading from http://ftp.uk.debian.org/debian/>
  - <mpg123_0.60.orig.tar.gz: downloading from http://ftp.uk.debian.org/debian/>
I: mpg123 [multiverse] -> mpg123-esd_0.59r-21 [multiverse].
I: mpg123 [multiverse] -> mpg123_0.59r-21 [multiverse].
I: mpg123 [multiverse] -> mpg123-nas_0.59r-21 [multiverse].
I: mpg123 [multiverse] -> mpg123-oss-3dnow_0.59r-21 [multiverse].
I: mpg123 [multiverse] -> mpg123-oss-i486_0.59r-21 [multiverse].

Changed in mpg123:
assignee: nobody → keybuk
status: Confirmed → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.