FFmpeg 6.0 upgrade. ---- update to 111.0.5563.64. Fixes the following security issues: CVE-2023-0927 CVE-2023-0928 CVE-2023-0929 CVE-2023-0930 CVE-2023-0931 CVE-2023-0932 CVE-2023-0933 CVE-2023-0941 CVE-2023-1213 CVE-2023-1214 CVE-2023-1215 CVE-2023-1216 CVE-2023-1217 CVE-2023-1218 CVE-2023-1219 CVE-2023-1220 CVE-2023-1221 CVE-2023-1222 CVE-2023-1223. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2023-a5e10b188a 2023-03-14 00:16:44.047436 --------------------------------------------------------------------------------Name : mpv Product : Fedora 38 Version : 0.35.1 Release : 3.fc38 URL : https://mpv.io/ Summary : Movie player playing most video formats and DVDs Description : Mpv is a movie player based on MPlayer and mplayer2. It supports a wide variety of video file formats, audio and video codecs, and subtitle types. Special input URL types are available to read input from a variety of sources other than disk files. Depending on platform, a variety of different video and audio output methods are supported. Mpv has an OpenGL, Vulkan, and D3D11 based video output that is capable of many features loved by videophiles, such as video scaling with popular high quality algorithms, color management, frame timing, interpolation, HDR, and more. While mpv strives for minimalism and provides no real GUI, it has a small controller on top of the video for basic control. Mpv can leverage most hardware decoding APIs on all platforms. Hardware decoding can be enabled at runtime on demand. Powerful scripting capabilities can make the player do almost anything. There is a large selection of user scripts on the wiki. A straightforward C API was designed from the ground up to make mpv usable as a library and facilitate easy integration into other applications. --------------------------------------------------------------------------------Update Information: FFmpeg 6.0 upgrade. ---- update to 111.0.5563.64. Fixes the following security issues: CVE-2023-0927 CVE-2023-0928 CVE-2023-0929 CVE-2023-0930 CVE-2023-0931 CVE-2023-0932 CVE-2023-0933 CVE-2023-0941 CVE-2023-1213 CVE-2023-1214 CVE-2023-1215 CVE-2023-1216 CVE-2023-1217 CVE-2023-1218 CVE-2023-1219 CVE-2023-1220 CVE-2023-1221 CVE-2023-1222 CVE-2023-1223 CVE-2023-1224 CVE-2023-1225 CVE-2023-1226 CVE-2023-1227 --------------------------------------------------------------------------------ChangeLog: * Sun Mar 12 2023 Neal Gompa - 0.35.1-3 - Rebuild for ffmpeg 6.0 --------------------------------------------------------------------------------References: [ 1 ] Bug #1944122 - notcurses-2.3.17 is available https://bugzilla.redhat.com/show_bug.cgi?id=1944122 [ 2 ] Bug #2022640 - notcurses-2.4.9 is available https://bugzilla.redhat.com/show_bug.cgi?id=2022640 [ 3 ] Bug #2028587 - notcurses-3.0.4 is available https://bugzilla.redhat.com/show_bug.cgi?id=2028587 [ 4 ] Bug #2045133 - notcurses: FTBFS in Fedora rawhide/f36 https://bugzilla.redhat.com/show_bug.cgi?id=2045133 [ 5 ] Bug #2053373 - notcurses-3.0.6 is available https://bugzilla.redhat.com/show_bug.cgi?id=2053373 [ 6 ] Bug #2172934 - CVE-2023-0927 CVE-2023-0928 CVE-2023-0929 CVE-2023-0930 CVE-2023-0931 CVE-2023-0932 CVE-2023-0933 CVE-2023-0941 chromium: various flaws [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2172934 [ 7 ] Bug #2173846 - ffmpeg-6.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2173846 [ 8 ] Bug #2174875 - k3b-22.12.3 is available https://bugzilla.redhat.com/show_bug.cgi?id=2174875 [ 9 ] Bug #2176135 - mlt-7.14.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2176135 [ 10 ] Bug #2176519 - CVE-2023-1213 CVE-2023-1214 CVE-2023-1215 CVE-2023-1216 CVE-2023-1217 CVE-2023-1218 CVE-2023-1219 CVE-2023-1220 CVE-2023-1221 CVE-2023-1222 CVE-2023-1223 CVE-2023-1224 CVE-2023-1225 CVE-2023-1226 CVE-2023-1227 ... chromium:various flaws [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2176519 [ 11 ] Bug #2176520 - CVE-2023-1213 CVE-2023-1214 CVE-2023-1215 CVE-2023-1216 CVE-2023-1217 CVE-2023-1218 CVE-2023-1219 CVE-2023-1220 CVE-2023-1221 CVE-2023-1222 CVE-2023-1223 CVE-2023-1224 CVE-2023-1225 CVE-2023-1226 CVE-2023-1227 ... chromium: various flaws [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2176520 [ 12 ] Bug #2177300 - retroarch-1.15.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2177300 [ 13 ] Bug #2177550 - nv-codec-headers-12.0.16.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2177550 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-a5e10b188a' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
An issue has been found in mpv, a video player based on MPlayer/mplayer2. Due to a use after free an attacker coudl execute arbitrary code or crash the program via the ao_c parameter. . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3358-1
A format string vulnerability was found in mpv, potentially resulting in arbitrary code execution.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202107-46 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: mpv: Format string vulnerability Date: July 20, 2021 Bugs: #780474 ID: 202107-46 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= A format string vulnerability was found in mpv, potentially resulting in arbitrary code execution. Background ========= Video player based on MPlayer/mplayer2. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 media-video/mpv < 0.33.1 > = 0.33.1 Description ========== mpv uses untrusted input within format strings. Impact ===== A remote attacker could entice a user to open a specially crafted m3u playlist file using mpv, possibly resulting in execution of arbitrary code with the privileges of the process or a Denial of Service condition. Workaround ========= There is no known workaround at this time. Resolution ========= All mpv users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =media-video/mpv-0.33.1" References ========= [ 1 ] CVE-2021-30145 https://nvd.nist.gov/vuln/detail/CVE-2021-30145 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202107-46 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality andsecurity of our users' machines is of utmost importance to us. Any security concerns should be addressed to
An update that fixes one vulnerability is now available. . openSUSE Security Update: Security update for mpv ______________________________________________________________________________ Announcement ID: openSUSE-SU-2021:0798-1 Rating: important References: #1186230 Cross-References: CVE-2021-30145 CVSS scores: CVE-2021-30145 (NVD) : 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Affected Products: openSUSE Backports SLE-15-SP2 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for mpv fixes the following issues: - CVE-2021-30145: Fixed format string vulnerability allows user-assisted remote attackers to achieve code execution via a crafted m3u playlist file (boo#1186230) This update was imported from the openSUSE:Leap:15.2:Update update project. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP2: zypper in -t patch openSUSE-2021-798=1 Package List: - openSUSE Backports SLE-15-SP2 (aarch64 ppc64le s390x x86_64): libmpv1-0.32.0+git.20200301T004003.e7bab0025f-bp152.2.6.1 mpv-0.32.0+git.20200301T004003.e7bab0025f-bp152.2.6.1 mpv-devel-0.32.0+git.20200301T004003.e7bab0025f-bp152.2.6.1 - openSUSE Backports SLE-15-SP2 (noarch): mpv-bash-completion-0.32.0+git.20200301T004003.e7bab0025f-bp152.2.6.1 mpv-zsh-completion-0.32.0+git.20200301T004003.e7bab0025f-bp152.2.6.1 References: https://www.suse.com/security/cve/CVE-2021-30145.html https://bugzilla.suse.com/1186230 . Critical patch release for Fedora addressing ffmpeg issue. Essential update code: FEDORA-SU-2023:0456-1.. openSUSE Security, mpv Update, Important Patch, Remote Code Execution,Format String Issue. . Severity: Important. LinuxSecurity.com Team
An update that fixes one vulnerability is now available. . openSUSE Security Update: Security update for mpv ______________________________________________________________________________ Announcement ID: openSUSE-SU-2021:0788-1 Rating: important References: #1186230 Cross-References: CVE-2021-30145 Affected Products: openSUSE Leap 15.2 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for mpv fixes the following issues: - CVE-2021-30145: Fixed format string vulnerability allows user-assisted remote attackers to achieve code execution via a crafted m3u playlist file (boo#1186230) Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.2: zypper in -t patch openSUSE-2021-788=1 Package List: - openSUSE Leap 15.2 (x86_64): libmpv1-0.32.0+git.20200301T004003.e7bab0025f-lp152.2.6.1 libmpv1-debuginfo-0.32.0+git.20200301T004003.e7bab0025f-lp152.2.6.1 mpv-0.32.0+git.20200301T004003.e7bab0025f-lp152.2.6.1 mpv-debuginfo-0.32.0+git.20200301T004003.e7bab0025f-lp152.2.6.1 mpv-debugsource-0.32.0+git.20200301T004003.e7bab0025f-lp152.2.6.1 mpv-devel-0.32.0+git.20200301T004003.e7bab0025f-lp152.2.6.1 - openSUSE Leap 15.2 (noarch): mpv-bash-completion-0.32.0+git.20200301T004003.e7bab0025f-lp152.2.6.1 mpv-zsh-completion-0.32.0+git.20200301T004003.e7bab0025f-lp152.2.6.1 References: https://www.suse.com/security/cve/CVE-2021-30145.html https://bugzilla.suse.com/1186230 . openSUSE publishes crucial security patch for mpv addressing a critical code execution vulnerability linked to format string defects.. openSUSE Security Update, mpv Code Execution, Software Patch. . Severity:Important. LinuxSecurity.com Team
A vulnerability has been found in mpv that may allow a remote attacker to execute arbitrary code.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 201805-05 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: High Title: mpv: Remote code execution Date: May 14, 2018 Bugs: #646886 ID: 201805-05 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= A vulnerability has been found in mpv that may allow a remote attacker to execute arbitrary code. Background ========= Video player based on MPlayer/mplayer2 Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 media-video/mpv < 0.27.2 > = 0.27.2 Description ========== A vulnerability was discovered in mpv with the handling of HTML documents containing VIDEO elements. Additionally, mpv accepts arbitrary URLs in a src attribute without a protocol whitelist in player/lua/ytdl_hook.lua. Impact ===== A remote attacker, by enticing the user to visit a specially crafted web site, could execute arbitrary code. Workaround ========= There is no known workaround at this time. Resolution ========= All mpv users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =media-video/mpv-0.27.2" References ========= [ 1 ] CVE-2018-6360 https://nvd.nist.gov/vuln/detail/CVE-2018-6360 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/201805-05 Concerns? ======== Security is a primary focusof Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to
Get the latest Linux and open source security news straight to your inbox.