-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 04 May 2016 12:03:02 +0200 Source: mplayer Binary: mplayer-gui mencoder mplayer mplayer-dbg mplayer-doc Architecture: source i386 all Version: 2:1.0~rc4.dfsg1+svn34540-1+deb7u2 Distribution: wheezy-security Urgency: high Maintainer: Debian multimedia packages maintainers <pkg-multimedia-maintainers@lists.alioth.debian.org> Changed-By: Thorsten Alteholz <debian@alteholz.de> Description: mencoder - MPlayer's Movie Encoder mplayer - movie player for Unix-like systems mplayer-dbg - debugging symbols for MPlayer mplayer-doc - documentation for MPlayer mplayer-gui - movie player for Unix-like systems Changes: mplayer (2:1.0~rc4.dfsg1+svn34540-1+deb7u2) wheezy-security; urgency=high . * Non-maintainer upload by the Wheezy LTS Team. * CVE-2016-4352 Mplayer is crashing when playing a fuzzed gif file. The gif demuxes assumes in many places that width*height is <= INT_MAX; this might not be true. Fixed by validating the picture size. Checksums-Sha1: 8a259ed8ebe6e924dfe128d47dd3086ce72da863 3602 mplayer_1.0~rc4.dfsg1+svn34540-1+deb7u2.dsc be40675ba3b67395fcb67d3c05702ba400fce6c0 13038465 mplayer_1.0~rc4.dfsg1+svn34540.orig.tar.gz 9acd7c7815585de19217b66081617db268172bbe 42236 mplayer_1.0~rc4.dfsg1+svn34540-1+deb7u2.debian.tar.gz 6b24d4192ca2e886c66cfc61bb728b78f7eab784 1929400 mplayer-gui_1.0~rc4.dfsg1+svn34540-1+deb7u2_i386.deb 2263ba422d96cb37315498123ec4724c594137c5 1397124 mencoder_1.0~rc4.dfsg1+svn34540-1+deb7u2_i386.deb aeda8569da22f59964d5b6126224373a4d967d99 2880786 mplayer_1.0~rc4.dfsg1+svn34540-1+deb7u2_i386.deb 3430bc037b9a32cbf66bb9800d459a5e180d8352 5801560 mplayer-dbg_1.0~rc4.dfsg1+svn34540-1+deb7u2_i386.deb 0d3c4e213d09a35e71c33ff88f0eeb6791e156fc 2277740 mplayer-doc_1.0~rc4.dfsg1+svn34540-1+deb7u2_all.deb Checksums-Sha256: db3be5be0b6fbd2a0c6dc3d4a943396ab4b8eed47dabd6e4d0027b22754179d7 3602 mplayer_1.0~rc4.dfsg1+svn34540-1+deb7u2.dsc 2327ac86b191d5f22d47d03004c83b68a5b8f29de7c1aade2e005d821f7223a1 13038465 mplayer_1.0~rc4.dfsg1+svn34540.orig.tar.gz 9054f29b0a3dc6fa6515930fcb3bb76f0f96a820a8f373b358df65c2d7072003 42236 mplayer_1.0~rc4.dfsg1+svn34540-1+deb7u2.debian.tar.gz eb19715a3ee2e31a1702054beb7ef73b302287458ce721559f1a96623cb0709d 1929400 mplayer-gui_1.0~rc4.dfsg1+svn34540-1+deb7u2_i386.deb 68d0687e9409f336e06325a8bd28e95cd41557b4b3a38a9ab1ba1d3cccefd186 1397124 mencoder_1.0~rc4.dfsg1+svn34540-1+deb7u2_i386.deb 235fdcc53fae7ce7b194ef402a0d1675e7bdf3cc3891bbfbcb23258373f9d4c4 2880786 mplayer_1.0~rc4.dfsg1+svn34540-1+deb7u2_i386.deb f8234e3074745a5623f39ed77bffff51b6a5b23e955950eaa6218e2fcd77102a 5801560 mplayer-dbg_1.0~rc4.dfsg1+svn34540-1+deb7u2_i386.deb 416f641c8a3352cf170a3b70f45da75ec11b04e0507b5a52a4f6d9b9b825e4c7 2277740 mplayer-doc_1.0~rc4.dfsg1+svn34540-1+deb7u2_all.deb Files: 3ce192399ecee369dff35f0ac198fa90 3602 video optional mplayer_1.0~rc4.dfsg1+svn34540-1+deb7u2.dsc 31915825dad8384489e52c3d2465b0d8 13038465 video optional mplayer_1.0~rc4.dfsg1+svn34540.orig.tar.gz 9d44d7c027dc91e150920544d85cb214 42236 video optional mplayer_1.0~rc4.dfsg1+svn34540-1+deb7u2.debian.tar.gz 535c1081d25d7a855393ea56973ab8aa 1929400 video optional mplayer-gui_1.0~rc4.dfsg1+svn34540-1+deb7u2_i386.deb e562d1a0dc1ee8e44b418714549fa2fd 1397124 video optional mencoder_1.0~rc4.dfsg1+svn34540-1+deb7u2_i386.deb 6a1cb49b74d595c53f20b7ed3ae64da1 2880786 video optional mplayer_1.0~rc4.dfsg1+svn34540-1+deb7u2_i386.deb 35a4444540bfd325c00d4941b05e81e6 5801560 debug extra mplayer-dbg_1.0~rc4.dfsg1+svn34540-1+deb7u2_i386.deb a34715a616fe1c2f380a39756a4bddc8 2277740 doc optional mplayer-doc_1.0~rc4.dfsg1+svn34540-1+deb7u2_all.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQJ8BAEBCgBmBQJXKj6YXxSAAAAAAC4AKGlzc3Vlci1mcHJAbm90YXRpb25zLm9w ZW5wZ3AuZmlmdGhob3JzZW1hbi5uZXQ2MjAxRkJGRkRCQkRFMDc4MjJFQUJCOTY5 NkZDQUMwRDM4N0I1ODQ3AAoJEJb8rA04e1hHDLIP/3gasbxHwOC+lgSKP0l+zBdm 07hy5mU0eMVlgiELRJhGeCc9IvMic5xzy/A2tBWKLomWuboShzRHHX3N+0U5TOkA GAuHTJFH/l9I3vJxGyEMVFEIFf/zkK311p8Yrq/9QyQS7ARf7Gs54PZEXQKeybyB PcKV0LPiLiARH/ckjaaJXaG9Au0qV2vz8K4e5UuoQe8RoxY6duRSj67CiA5QhBk8 v7Hvpc5D9U/2wbg9x5o1QKO1ZZun9KbamX03iHE6Q2M3KY8USxFQvApNp+LsScqJ HKdxJbotiu81ykjgVYS3+krjmP8vAL946U1KGJ0YRrFBLSWegRx2fqgq35O7J9dm x0wNqzz3P1aqVmh8fPD9yAuER2+wIuxgXQx55iy5z40oy9ZZ5y4r3IALtVGNYi5l h4ViOf7UD7VswLySfgFj7TK9ZSq8JkEV0O80E6srAU19PsOI7Rru6jFYG3UA/vA3 NcxOY5i3DPtuBADXWzNcCEPpx4/Ji29Y/9iYWG9aNtNKjeGfTSDkCTzSoS/eV+5i 9R8X9OCIIa9PNDHYPQzwSSR9Qx6oZ8xdUhChCUduFm3eaCo4VqrHUfX8T+rmqU2N ZGn6ViRSPqD1oLC8QLlZMJP194X4SdAYM0agT2RHejiWcqcPOQXbyK9ejJ42bIwU HyI+auc0SBFTJnVgc04N =A+Ng -----END PGP SIGNATURE-----