--------------------------------------------------------------------------------Fedora Update Notification
FEDORA-2017-c89d94d812
2017-09-20 20:33:19.202821
--------------------------------------------------------------------------------Name        : mpg123
Product     : Fedora 26
Version     : 1.25.6
Release     : 1.fc26
URL         : http://mpg123.org
Summary     : Real time MPEG 1.0/2.0/2.5 audio player/decoder for layers 1, 2 and 3
Description :
Real time MPEG 1.0/2.0/2.5 audio player/decoder for layers 1, 2 and 3 (most
commonly MPEG 1.0 layer 3 aka MP3), as well as re-usable decoding and output
libraries.

--------------------------------------------------------------------------------Update Information:

Update to upstream release 1.25.6
--------------------------------------------------------------------------------References:

  [ 1 ] Bug #1480322 - Update for mpg123
        https://bugzilla.redhat.com/show_bug.cgi?id=1480322
  [ 2 ] Bug #1470104 - CVE-2017-10683 CVE-2017-11126 CVE-2017-9545 CVE-2017-12797 mpg123: Multiple vulnerabilities [fedora-all]
        https://bugzilla.redhat.com/show_bug.cgi?id=1470104
  [ 3 ] Bug #1465819 - There is a heap buffer overflow in mpg123 latest version.
        https://bugzilla.redhat.com/show_bug.cgi?id=1465819
  [ 4 ] Bug #1442278 - ALSA module skips beginning of any mp3 file
        https://bugzilla.redhat.com/show_bug.cgi?id=1442278
  [ 5 ] Bug #1428195 - mpg123-1.25.6 is available
        https://bugzilla.redhat.com/show_bug.cgi?id=1428195
--------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade mpg123' at the command line.
For more information, refer to the dnf documentation available at
https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/security/
--------------------------------------------------------------------------------
_______________________________________________
package-announce mailing list -- package-announce@lists.fedoraproject.org
To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Fedora 26: mpg123 Security Update

September 20, 2017
Update to upstream release 1.25.6

Summary

Real time MPEG 1.0/2.0/2.5 audio player/decoder for layers 1, 2 and 3 (most

commonly MPEG 1.0 layer 3 aka MP3), as well as re-usable decoding and output

libraries.

Update to upstream release 1.25.6

[ 1 ] Bug #1480322 - Update for mpg123

https://bugzilla.redhat.com/show_bug.cgi?id=1480322

[ 2 ] Bug #1470104 - CVE-2017-10683 CVE-2017-11126 CVE-2017-9545 CVE-2017-12797 mpg123: Multiple vulnerabilities [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=1470104

[ 3 ] Bug #1465819 - There is a heap buffer overflow in mpg123 latest version.

https://bugzilla.redhat.com/show_bug.cgi?id=1465819

[ 4 ] Bug #1442278 - ALSA module skips beginning of any mp3 file

https://bugzilla.redhat.com/show_bug.cgi?id=1442278

[ 5 ] Bug #1428195 - mpg123-1.25.6 is available

https://bugzilla.redhat.com/show_bug.cgi?id=1428195

su -c 'dnf upgrade mpg123' at the command line.

For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

FEDORA-2017-c89d94d812 2017-09-20 20:33:19.202821 Product : Fedora 26 Version : 1.25.6 Release : 1.fc26 URL : http://mpg123.org Summary : Real time MPEG 1.0/2.0/2.5 audio player/decoder for layers 1, 2 and 3 Description : Real time MPEG 1.0/2.0/2.5 audio player/decoder for layers 1, 2 and 3 (most commonly MPEG 1.0 layer 3 aka MP3), as well as re-usable decoding and output libraries. Update to upstream release 1.25.6 [ 1 ] Bug #1480322 - Update for mpg123 https://bugzilla.redhat.com/show_bug.cgi?id=1480322 [ 2 ] Bug #1470104 - CVE-2017-10683 CVE-2017-11126 CVE-2017-9545 CVE-2017-12797 mpg123: Multiple vulnerabilities [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1470104 [ 3 ] Bug #1465819 - There is a heap buffer overflow in mpg123 latest version. https://bugzilla.redhat.com/show_bug.cgi?id=1465819 [ 4 ] Bug #1442278 - ALSA module skips beginning of any mp3 file https://bugzilla.redhat.com/show_bug.cgi?id=1442278 [ 5 ] Bug #1428195 - mpg123-1.25.6 is available https://bugzilla.redhat.com/show_bug.cgi?id=1428195 su -c 'dnf upgrade mpg123' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ package-announce mailing list -- package-announce@lists.fedoraproject.org To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Change Log

References

Update Instructions

Severity
Product : Fedora 26
Version : 1.25.6
Release : 1.fc26
URL : http://mpg123.org
Summary : Real time MPEG 1.0/2.0/2.5 audio player/decoder for layers 1, 2 and 3

Related News