MGASA-2014-0071

Source
https://advisories.mageia.org/MGASA-2014-0071.html
Import Source
https://advisories.mageia.org/MGASA-2014-0071.json
JSON Data
https://api.test.osv.dev/v1/vulns/MGASA-2014-0071
Related
Published
2014-02-16T12:54:48Z
Modified
2014-02-16T12:54:45Z
Summary
Updated xbmc package fixes a security vulnerability
Details

Due to flaws in the embedded copy of libDCR, a fork of dcraw.c, in the embedded copy of CxImage, opening a specially crafted photo file could trigger a division by zero, an infinite loop, or a null pointer dereference, resulting in a denial of service (CVE-2013-1438).

This update fixes those flaws.

XBMC is also updated to a newer bugfix-only release, version 12.3. It contains fixes to various issues, including: - several PVR related bugs - memory leaks - audio channel mapping - possible crash on progress dialog and more.

Additionally, this update fixes a compatibility issue on Mageia 4 affecting AC-3 transcoding, which prevented, for example, multichannel playback of AAC 5.1 files over S/PDIF or stereo-only HDMI devices.

The PVR addons have also been updated.

References
Credits

Affected packages

Mageia:4 / xbmc

Package

Name
xbmc
Purl
pkg:rpm/mageia/xbmc?distro=mageia-4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
12.3-1.1.mga4

Ecosystem specific

{
    "section": "core"
}

Mageia:3 / xbmc

Package

Name
xbmc
Purl
pkg:rpm/mageia/xbmc?distro=mageia-3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
12.3-1.1.mga3

Ecosystem specific

{
    "section": "core"
}