Bug#498243: xine-lib: multiple heap overflows

2008-10-25 Thread David Moreno
tags 498243 + upstream severity 498243 important stop Issues 3A-3G haven't been addressed yet by Xine, not even in release 1.1.15, tagging upstream. As Reinhard Tartler suggests, the severity can be downgraded now; the remaining issues subjected "unexpected process termination and other issues" a

Bug#498243: xine-lib: multiple heap overflows

2008-09-19 Thread Ben Hutchings
Darren Salt is a maintainer of both upstream xine-lib and the Debian package. It appears that he has applied all the upstream security fixes since 1.1.14 to the Debian package as well. That leaves issues 1B-1D to be checked and 3A-3G to be addressed. Ben. signature.asc Description: This is a

Bug#498243: xine-lib: multiple heap overflows

2008-09-08 Thread Steffen Joeris
Package: xine-lib Severity: grave Tags: security Justification: user security hole Hi, As you are probably aware oCERT released an advisory[0] about several issues they found in xine-lib. I am just wondering, how we are going to address the debian versions? Cheers Steffen [0]: http://www.ocert.