MGASA-2014-0071
Dashboard / Vulnerabilities / MGASA-2014-0071
Summary: Updated xbmc package fixes a security vulnerability
Details: Due to flaws in the embedded copy of libDCR, a fork of dcraw.c, in the embedded copy of CxImage, opening a specially crafted photo file could trigger a division by zero, an infinite loop, or a null pointer dereference, resulting in a denial of service (CVE-2013-1438). This update fixes those flaws. XBMC is also updated to a newer bugfix-only release, version 12.3. It contains fixes to various issues, including: - several PVR related bugs - memory leaks - audio channel mapping - possible crash on progress dialog and more. Additionally, this update fixes a compatibility issue on Mageia 4 affecting AC-3 transcoding, which prevented, for example, multichannel playback of AAC 5.1 files over S/PDIF or stereo-only HDMI devices. The PVR addons have also been updated.
References: https://advisories.mageia.org/MGASA-2014-0071.html, https://bugs.mageia.org/show_bug.cgi?id=12613, https://bugs.mageia.org/show_bug.cgi?id=11149, http://xbmc.org/xbmc-12-3-frodo-fixes/
Affected packages
Package
Name: xbmc
Purl: pkg:rpm/mageia/xbmc?arch=source&distro=mageia-3
Affected ranges
Type: ECOSYSTEM
Events:
