Format: 1.7 Date: Thu, 15 Dec 2005 12:33:12 +0000 Source: xine-lib Binary: libxine-dev libxine1 Architecture: ia64 Version: 1.0-1ubuntu3.4 Distribution: autobuild Urgency: low Maintainer: Ubuntu/ia64 Build Daemon Changed-By: Martin Pitt Description: libxine-dev - the xine video player library, development packages libxine1 - the xine video/media player library, binary files Changes: xine-lib (1.0-1ubuntu3.4) hoary-updates; urgency=low . * SECURITY UPDATE: Fix arbitrary code execution with crafted PNG images in embedded ffmpeg copy. * src/libffmpeg/libavcodec/utils.c, avcodec_default_get_buffer(): Apply upstream patch to fix buffer overflow on decoding of small PIX_FMT_PAL8 PNG files. * References: CVE-2005-4048 http://mplayerhq.hu/pipermail/ffmpeg-devel/2005-November/005333.html http://www1.mplayerhq.hu/cgi-bin/cvsweb.cgi/ffmpeg/libavcodec/ utils.c.diff?r1=1.161&r2=1.162&cvsroot=FFMpeg Files: aef60f40b8e253b03fca953b648689e6 106748 libdevel optional libxine-dev_1.0-1ubuntu3.4_ia64.deb 3c0f496fe2ba7abf333921a7374d4ca6 5152600 libs optional libxine1_1.0-1ubuntu3.4_ia64.deb