FFmpeg 6.0 upgrade. ---- update to 111.0.5563.64. Fixes the following security issues: CVE-2023-0927 CVE-2023-0928 CVE-2023-0929 CVE-2023-0930 CVE-2023-0931 CVE-2023-0932 CVE-2023-0933 CVE-2023-0941 CVE-2023-1213 CVE-2023-1214 CVE-2023-1215 CVE-2023-1216 CVE-2023-1217 CVE-2023-1218 CVE-2023-1219 CVE-2023-1220 CVE-2023-1221 CVE-2023-1222 CVE-2023-1223. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2023-a5e10b188a 2023-03-14 00:16:44.047436 --------------------------------------------------------------------------------Name : audacious-plugins Product : Fedora 38 Version : 4.3 Release : 2.fc38 URL : https://audacious-media-player.org/ Summary : Plugins for the Audacious audio player Description : This package provides essential plugins for the Audacious audio player. --------------------------------------------------------------------------------Update Information: FFmpeg 6.0 upgrade. ---- update to 111.0.5563.64. Fixes the following security issues: CVE-2023-0927 CVE-2023-0928 CVE-2023-0929 CVE-2023-0930 CVE-2023-0931 CVE-2023-0932 CVE-2023-0933 CVE-2023-0941 CVE-2023-1213 CVE-2023-1214 CVE-2023-1215 CVE-2023-1216 CVE-2023-1217 CVE-2023-1218 CVE-2023-1219 CVE-2023-1220 CVE-2023-1221 CVE-2023-1222 CVE-2023-1223 CVE-2023-1224 CVE-2023-1225 CVE-2023-1226 CVE-2023-1227 --------------------------------------------------------------------------------ChangeLog: * Sun Mar 12 2023 Neal Gompa - 4.3-2 - Rebuild for ffmpeg 6.0 --------------------------------------------------------------------------------References: [ 1 ] Bug #1944122 - notcurses-2.3.17 is available https://bugzilla.redhat.com/show_bug.cgi?id=1944122 [ 2 ] Bug #2022640 - notcurses-2.4.9 is available https://bugzilla.redhat.com/show_bug.cgi?id=2022640 [ 3 ] Bug #2028587 - notcurses-3.0.4 is available https://bugzilla.redhat.com/show_bug.cgi?id=2028587 [ 4 ] Bug #2045133 -notcurses: FTBFS in Fedora rawhide/f36 https://bugzilla.redhat.com/show_bug.cgi?id=2045133 [ 5 ] Bug #2053373 - notcurses-3.0.6 is available https://bugzilla.redhat.com/show_bug.cgi?id=2053373 [ 6 ] Bug #2172934 - CVE-2023-0927 CVE-2023-0928 CVE-2023-0929 CVE-2023-0930 CVE-2023-0931 CVE-2023-0932 CVE-2023-0933 CVE-2023-0941 chromium: various flaws [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2172934 [ 7 ] Bug #2173846 - ffmpeg-6.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2173846 [ 8 ] Bug #2174875 - k3b-22.12.3 is available https://bugzilla.redhat.com/show_bug.cgi?id=2174875 [ 9 ] Bug #2176135 - mlt-7.14.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2176135 [ 10 ] Bug #2176519 - CVE-2023-1213 CVE-2023-1214 CVE-2023-1215 CVE-2023-1216 CVE-2023-1217 CVE-2023-1218 CVE-2023-1219 CVE-2023-1220 CVE-2023-1221 CVE-2023-1222 CVE-2023-1223 CVE-2023-1224 CVE-2023-1225 CVE-2023-1226 CVE-2023-1227 ... chromium: various flaws [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2176519 [ 11 ] Bug #2176520 - CVE-2023-1213 CVE-2023-1214 CVE-2023-1215 CVE-2023-1216 CVE-2023-1217 CVE-2023-1218 CVE-2023-1219 CVE-2023-1220 CVE-2023-1221 CVE-2023-1222 CVE-2023-1223 CVE-2023-1224 CVE-2023-1225 CVE-2023-1226 CVE-2023-1227 ... chromium: various flaws [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2176520 [ 12 ] Bug #2177300 - retroarch-1.15.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2177300 [ 13 ] Bug #2177550 - nv-codec-headers-12.0.16.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2177550 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-a5e10b188a' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html Allpackages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
It has been discovered a NULL pointer dereference could happen in ncmpc, an ncurses-based audio player. This could result in a crash and a denial of service. . Package : ncmpc Version : 0.24-1+deb8u1 CVE ID : CVE-2018-9240 It has been discovered a NULL pointer dereference could happen in ncmpc, an ncurses-based audio player. This could result in a crash and a denial of service. For Debian 8 "Jessie", this problem has been fixed in version 0.24-1+deb8u1. We recommend that you upgrade your ncmpc packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Segmentation fault identified within mpd client framework, affecting operational integrity and leading to disruption of user services.. NULL Pointer, Denial of Service, ncmpc, Debian, Security Update. . Severity: Critical. LinuxSecurity.com Team
Update to upstream release 1.25.6. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2017-12794057a6 2017-09-30 05:57:53.267973 --------------------------------------------------------------------------------Name : mpg123 Product : Fedora 27 Version : 1.25.6 Release : 1.fc27 URL : http://mpg123.org Summary : Real time MPEG 1.0/2.0/2.5 audio player/decoder for layers 1, 2 and 3 Description : Real time MPEG 1.0/2.0/2.5 audio player/decoder for layers 1, 2 and 3 (most commonly MPEG 1.0 layer 3 aka MP3), as well as re-usable decoding and output libraries. --------------------------------------------------------------------------------Update Information: Update to upstream release 1.25.6 --------------------------------------------------------------------------------References: [ 1 ] Bug #1480322 - Update for mpg123 https://bugzilla.redhat.com/show_bug.cgi?id=1480322 [ 2 ] Bug #1470104 - CVE-2017-10683 CVE-2017-11126 CVE-2017-9545 CVE-2017-12797 mpg123: Multiple vulnerabilities [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1470104 [ 3 ] Bug #1465819 - There is a heap buffer overflow in mpg123 latest version. https://bugzilla.redhat.com/show_bug.cgi?id=1465819 [ 4 ] Bug #1442278 - ALSA module skips beginning of any mp3 file https://bugzilla.redhat.com/show_bug.cgi?id=1442278 [ 5 ] Bug #1428195 - mpg123-1.25.6 is available https://bugzilla.redhat.com/show_bug.cgi?id=1428195 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade mpg123' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Update to upstream release 1.25.6. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2017-172410ec92 2017-09-22 15:26:37.735085 --------------------------------------------------------------------------------Name : mpg123 Product : Fedora 25 Version : 1.25.6 Release : 1.fc25 URL : http://mpg123.org Summary : Real time MPEG 1.0/2.0/2.5 audio player/decoder for layers 1, 2 and 3 Description : Real time MPEG 1.0/2.0/2.5 audio player/decoder for layers 1, 2 and 3 (most commonly MPEG 1.0 layer 3 aka MP3), as well as re-usable decoding and output libraries. --------------------------------------------------------------------------------Update Information: Update to upstream release 1.25.6 --------------------------------------------------------------------------------References: [ 1 ] Bug #1480322 - Update for mpg123 https://bugzilla.redhat.com/show_bug.cgi?id=1480322 [ 2 ] Bug #1470104 - CVE-2017-10683 CVE-2017-11126 CVE-2017-9545 CVE-2017-12797 mpg123: Multiple vulnerabilities [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1470104 [ 3 ] Bug #1465819 - There is a heap buffer overflow in mpg123 latest version. https://bugzilla.redhat.com/show_bug.cgi?id=1465819 [ 4 ] Bug #1442278 - ALSA module skips beginning of any mp3 file https://bugzilla.redhat.com/show_bug.cgi?id=1442278 [ 5 ] Bug #1428195 - mpg123-1.25.6 is available https://bugzilla.redhat.com/show_bug.cgi?id=1428195 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade mpg123' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Update to upstream release 1.25.6. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2017-c89d94d812 2017-09-20 20:33:19.202821 --------------------------------------------------------------------------------Name : mpg123 Product : Fedora 26 Version : 1.25.6 Release : 1.fc26 URL : http://mpg123.org Summary : Real time MPEG 1.0/2.0/2.5 audio player/decoder for layers 1, 2 and 3 Description : Real time MPEG 1.0/2.0/2.5 audio player/decoder for layers 1, 2 and 3 (most commonly MPEG 1.0 layer 3 aka MP3), as well as re-usable decoding and output libraries. --------------------------------------------------------------------------------Update Information: Update to upstream release 1.25.6 --------------------------------------------------------------------------------References: [ 1 ] Bug #1480322 - Update for mpg123 https://bugzilla.redhat.com/show_bug.cgi?id=1480322 [ 2 ] Bug #1470104 - CVE-2017-10683 CVE-2017-11126 CVE-2017-9545 CVE-2017-12797 mpg123: Multiple vulnerabilities [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1470104 [ 3 ] Bug #1465819 - There is a heap buffer overflow in mpg123 latest version. https://bugzilla.redhat.com/show_bug.cgi?id=1465819 [ 4 ] Bug #1442278 - ALSA module skips beginning of any mp3 file https://bugzilla.redhat.com/show_bug.cgi?id=1442278 [ 5 ] Bug #1428195 - mpg123-1.25.6 is available https://bugzilla.redhat.com/show_bug.cgi?id=1428195 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade mpg123' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
An update to the latest release, includes new features such as queuing, playlist search and filtering as well as "stop after current track". And, long awaited and finally available: sorting the collection by composer. Also includes a security fix concerning the parsing of malformed Audible digital audio files. For further details, see . --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2009-0550 2009-01-14 23:38:39 --------------------------------------------------------------------------------Name : amarok Product : Fedora 10 Version : 2.0.1.1 Release : 1.fc10 URL : https://amarok.kde.org/ Summary : Media player Description : Amarok is a multimedia player with: - fresh playlist concept, very fast to use, with drag and drop - plays all formats supported by the various engines - audio effects, like reverb and compressor - compatible with the .m3u and .pls formats for playlists - nice GUI, integrates into the KDE look, but with a unique touch --------------------------------------------------------------------------------Update Information: An update to the latest release, includes new features such as queuing, playlist search and filtering as well as "stop after current track". And, long awaited and finally available: sorting the collection by composer. Also includes a security fix concerning the parsing of malformed Audible digital audio files. For further details, see --------------------------------------------------------------------------------ChangeLog: * Fri Jan 9 2009 Rex Dieter - 2.0.1.1-1 - amarok-2.0.1.1 * Tue Jan 6 2009 Rex Dieter - 2.0.1-1 - amarok-2.0.1 * Tue Dec 9 2008 Rex Dieter - 2.0-2 - respin tarball * Fri Dec 5 2008 Rex Dieter - 2.0-1 - amarok-2.0 (final, first cut) * Fri Nov 21 2008 Rex Dieter - 1.98-1 - amarok-1.98 (2rc1) --------------------------------------------------------------------------------References: [ 1 ] Bug#479560 - amarok: multiple buffer overflows when parsing Audible .aa files https://bugzilla.redhat.com/show_bug.cgi?id=479560 --------------------------------------------------------------------------------This update can be installed with the "yum" update program. Use su -c 'yum update amarok' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ Fedora-package-announce mailing list
Get the latest Linux and open source security news straight to your inbox.