From owner-freebsd-ports-bugs@FreeBSD.ORG Mon Dec 20 22:00:52 2004 Return-Path: Delivered-To: freebsd-ports-bugs@hub.freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id B255A16A58C for ; Mon, 20 Dec 2004 22:00:52 +0000 (GMT) Received: from freefall.freebsd.org (freefall.freebsd.org [216.136.204.21]) by mx1.FreeBSD.org (Postfix) with ESMTP id 8059E43D4C for ; Mon, 20 Dec 2004 22:00:52 +0000 (GMT) (envelope-from gnats@FreeBSD.org) Received: from freefall.freebsd.org (gnats@localhost [127.0.0.1]) by freefall.freebsd.org (8.13.1/8.13.1) with ESMTP id iBKM0q9L032782 for ; Mon, 20 Dec 2004 22:00:52 GMT (envelope-from gnats@freefall.freebsd.org) Received: (from gnats@localhost) by freefall.freebsd.org (8.13.1/8.13.1/Submit) id iBKM0qSd032779; Mon, 20 Dec 2004 22:00:52 GMT (envelope-from gnats) Resent-Date: Mon, 20 Dec 2004 22:00:52 GMT Resent-Message-Id: <200412202200.iBKM0qSd032779@freefall.freebsd.org> Resent-From: FreeBSD-gnats-submit@FreeBSD.org (GNATS Filer) Resent-To: freebsd-ports-bugs@FreeBSD.org Resent-Reply-To: FreeBSD-gnats-submit@FreeBSD.org, "Thomas E. Zander" Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id A830C16A4CE for ; Mon, 20 Dec 2004 21:52:57 +0000 (GMT) Received: from mail-out.m-online.net (mail-out.m-online.net [212.18.0.9]) by mx1.FreeBSD.org (Postfix) with ESMTP id 2FB0643D41 for ; Mon, 20 Dec 2004 21:52:57 +0000 (GMT) (envelope-from riggs@rrr.de) Received: from mail.m-online.net (svr20.m-online.net [192.168.3.148]) by mail-out.m-online.net (Postfix) with ESMTP id B4AAB4CC5 for ; Mon, 20 Dec 2004 22:52:53 +0100 (CET) Received: from marvin.riggiland.au (ppp-82-135-0-36.mnet-online.de [82.135.0.36]) by mail.m-online.net (Postfix) with ESMTP id 31AFA19383 for ; Mon, 20 Dec 2004 22:52:27 +0100 (CET) Received: from marvin.riggiland.au (localhost [127.0.0.1]) by marvin.riggiland.au (8.13.1/8.13.1) with ESMTP id iBKLqqMY052684 for ; Mon, 20 Dec 2004 22:52:52 +0100 (CET) (envelope-from riggs@marvin.riggiland.au) Received: (from riggs@localhost) by marvin.riggiland.au (8.13.1/8.13.1/Submit) id iBKLqqti052683; Mon, 20 Dec 2004 22:52:52 +0100 (CET) (envelope-from riggs) Message-Id: <200412202152.iBKLqqti052683@marvin.riggiland.au> Date: Mon, 20 Dec 2004 22:52:52 +0100 (CET) From: "Thomas E. Zander" To: FreeBSD-gnats-submit@FreeBSD.org X-Send-Pr-Version: 3.113 Subject: ports/75336: [MAINTAINER-UPDATE] multimedia/mplayer X-BeenThere: freebsd-ports-bugs@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list List-Id: Ports bug reports List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 20 Dec 2004 22:00:52 -0000 >Number: 75336 >Category: ports >Synopsis: [MAINTAINER-UPDATE] multimedia/mplayer >Confidential: no >Severity: serious >Priority: medium >Responsible: freebsd-ports-bugs >State: open >Quarter: >Keywords: >Date-Required: >Class: maintainer-update >Submitter-Id: current-users >Arrival-Date: Mon Dec 20 22:00:52 GMT 2004 >Closed-Date: >Last-Modified: >Originator: Thomas E. Zander >Release: FreeBSD 5.3-RELEASE-p2 i386 >Organization: >Environment: System: FreeBSD marvin.riggiland.au 5.3-RELEASE-p2 FreeBSD 5.3-RELEASE-p2 #3: Thu Dec 2 14:40:54 CET 2004 root@marvin.riggiland.au:/usr/obj/usr/src/sys/MARVIN i386 >Description: Several security flaws have been detected in mplayer's streaming code base, including o Potential heap overflow in Real RTSP streaming code o Potential stack overflow in MMST streaming code o Multiple buffer overflows in BMP demuxer o Potential heap overflow in pnm streaming code o Potential buffer overflow in mp3lib >How-To-Repeat: >Fix: The -try2 release contains fixes for these vulnerabilities. Patch for the multimedia/mplayer port as follows: diff -ruN mplayer-old/Makefile mplayer/Makefile --- mplayer-old/Makefile Tue Nov 16 08:17:49 2004 +++ mplayer/Makefile Mon Dec 20 21:54:43 2004 @@ -243,7 +243,7 @@ PORTNAME= mplayer PORTVERSION= 0.99.5 -PORTREVISION= 4 +PORTREVISION= 5 CATEGORIES= multimedia audio ipv6 MASTER_SITES= http://www1.mplayerhq.hu/MPlayer/releases/ \ http://www2.mplayerhq.hu/MPlayer/releases/ \ @@ -255,7 +255,7 @@ ftp://ftp.lug.udel.edu/MPlayer/releases/ \ ftp://mirrors.xmission.com/MPlayer/releases/ \ http://www.rrr.de/~riggs/mplayer/ -DISTNAME= MPlayer-1.0pre5 +DISTNAME= MPlayer-1.0pre5try2 MAINTAINER= riggs@rrr.de COMMENT= High performance media player/encoder supporting many formats diff -ruN mplayer-old/distinfo mplayer/distinfo --- mplayer-old/distinfo Thu Aug 19 19:42:17 2004 +++ mplayer/distinfo Mon Dec 20 21:55:52 2004 @@ -1,4 +1,4 @@ -MD5 (MPlayer-1.0pre5.tar.bz2) = fbe6919eb025526e8ed129cd61a49969 -SIZE (MPlayer-1.0pre5.tar.bz2) = 5072836 +MD5 (MPlayer-1.0pre5try2.tar.bz2) = 724c905a8dddb7e8ec9722fc585f833d +SIZE (MPlayer-1.0pre5try2.tar.bz2) = 5073725 MD5 (mplayer1.0pre5-gtk2-20040730.patch.bz2) = 49840e54549f47fa859d0c3d27014202 SIZE (mplayer1.0pre5-gtk2-20040730.patch.bz2) = 38845 >Release-Note: >Audit-Trail: >Unformatted: