Format: 1.8 Date: Mon, 19 Jan 2009 22:05:24 +0100 Source: amarok Binary: amarok amarok-common amarok-engines amarok-engine-xine amarok-engine-yauap amarok-dbg Architecture: lpia_translations lpia Version: 2:1.4.10-0ubuntu3.1 Distribution: intrepid Urgency: low Maintainer: Ubuntu/lpia Build Daemon Changed-By: Harald Sitter Description: amarok - versatile and easy to use audio player for KDE amarok-common - architecture independent files for Amarok amarok-dbg - debugging symbols for Amarok amarok-engine-xine - xine engine for the Amarok audio player amarok-engine-yauap - Yauap engine for the Amarok audio player amarok-engines - output engines for the Amarok music player Launchpad-Bugs-Fixed: 318555 Changes: amarok (2:1.4.10-0ubuntu3.1) intrepid-security; urgency=low . * SECURITY UPDATE: integer overflows allow remote attackers to execute arbitrary code via an Audible Audio (.aa) file (LP: #318555) - debian/patches/security_audible_tags.diff fix integer overflow while reading audible aa file tags. Based on upstream patch. - http://websvn.kde.org/?view=rev&revision=908415 - http://www.trapkit.de/advisories/TKADV2009-002.txt - CVE-2009-0135 - CVE-2009-0136 Checksums-Sha1: e65126c68803947733fc6752a2c315ae6116a565 5396216 amarok_1.4.10-0ubuntu3.1_lpia_translations.tar.gz 04bfdb61c2e57f4df9b2e3fe2c8c00b0ba0ec472 2466854 amarok_1.4.10-0ubuntu3.1_lpia.deb 19241578e14ab731db3f8540b5593bf38faad412 72996 amarok-engine-xine_1.4.10-0ubuntu3.1_lpia.deb 5bfa482851c3d650cb2295c0d2b258ed83255758 42324 amarok-engine-yauap_1.4.10-0ubuntu3.1_lpia.deb a114cdb2210d8057b922f066518bc6d80f04a08a 11001132 amarok-dbg_1.4.10-0ubuntu3.1_lpia.deb Checksums-Sha256: f6dd92ba5247679bf75219499ba38050016fd4e48cffba24bf79d1e2d81f3e14 5396216 amarok_1.4.10-0ubuntu3.1_lpia_translations.tar.gz 8312ff362760c94ebd9a301b0b62b0c92afaa4cd36e9ceb07217e0d1e444068e 2466854 amarok_1.4.10-0ubuntu3.1_lpia.deb e32e268225ac739ddc8fd3f5b9addec495f6d68840e6c17aa7102639c3e632fc 72996 amarok-engine-xine_1.4.10-0ubuntu3.1_lpia.deb 81950a83b736168aa87718f303bdd77066511f5a60ac5aa70351fe17b2a5ae70 42324 amarok-engine-yauap_1.4.10-0ubuntu3.1_lpia.deb e1490805df67379b0d870d877b1e41f01fe1909f6139e3e92fb05f20eb731e95 11001132 amarok-dbg_1.4.10-0ubuntu3.1_lpia.deb Files: c55f6b7f40c6ae33a6f334424890124d 5396216 raw-translations - amarok_1.4.10-0ubuntu3.1_lpia_translations.tar.gz 1e8371a2ecd057dd132b734dd90123ae 2466854 kde optional amarok_1.4.10-0ubuntu3.1_lpia.deb 700366415eb1979682355bf3321116eb 72996 kde optional amarok-engine-xine_1.4.10-0ubuntu3.1_lpia.deb 46e91ba8d21b8a07bb55908baa31ff36 42324 kde optional amarok-engine-yauap_1.4.10-0ubuntu3.1_lpia.deb 58d91d53551248da242004538f8cf4e1 11001132 kde extra amarok-dbg_1.4.10-0ubuntu3.1_lpia.deb Original-Maintainer: Modestas Vainius