Debian Package Tracker
Register | Log in
Subscribe

libquicktime

Choose email to subscribe with

general
  • source: libquicktime (main)
  • version: 2:1.2.4-12
  • maintainer: Debian Multimedia Maintainers (archive) [DMD]
  • uploaders: Loic Minier [DMD] – Reinhard Tartler [DMD]
  • arch: all any
  • std-ver: 3.9.8
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • o-o-stable: 2:1.2.4-3
  • o-o-sec: 2:1.2.4-3+deb7u2
  • oldstable: 2:1.2.4-7+deb8u1
  • old-sec: 2:1.2.4-7+deb8u1
  • stable: 2:1.2.4-10+deb9u1
  • testing: 2:1.2.4-12
  • unstable: 2:1.2.4-12
versioned links
  • 2:1.2.4-3: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 2:1.2.4-3+deb7u2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 2:1.2.4-7+deb8u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 2:1.2.4-10+deb9u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 2:1.2.4-12: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • libquicktime-dev
  • libquicktime-doc
  • libquicktime2
  • quicktime-utils
  • quicktime-x11utils
action needed
Standards version of the package is outdated. high
The package is severely out of date with respect to the Debian Policy. The package should be updated to follow the last version of Debian Policy (Standards-Version 4.3.0 instead of 3.9.8).
Created: 2017-07-01 Last update: 2018-12-23 17:15
Depends on packages which need a new maintainer normal
The packages that libquicktime depends on which need a new maintainer are:
  • libdv (#814889)
    • Depends: libdv4
    • Build-Depends: libdv4-dev
Created: 2017-12-02 Last update: 2019-02-24 00:09
1 new commit since last upload, time to release? normal
vcswatch reports that this package seems to have new commits in its VCS but has not yet updated debian/changelog. You should consider updating the Debian changelog and uploading this new version into the archive.

Here are the relevant commit logs:
commit 035c123b048fd31feea2b218de4daa784106d5ad
Author: Ondřej Nový <onovy@debian.org>
Date:   Mon Oct 1 08:36:15 2018 +0200

    d/watch: Use https protocol
Created: 2018-10-02 Last update: 2019-02-23 19:39
lintian reports 20 warnings normal
Lintian reports 20 warnings about this package. You should make the package lintian clean getting rid of them.
Created: 2018-10-17 Last update: 2018-10-17 05:09
7 ignored security issues in jessie low
There are 7 open security issues in jessie.
7 issues skipped by the security teams:
  • CVE-2017-9123: The lqt_frame_duration function in lqt_quicktime.c in libquicktime 1.2.4 allows remote attackers to cause a denial of service (invalid memory read and application crash) via a crafted mp4 file.
  • CVE-2017-9127: The quicktime_user_atoms_read_atom function in useratoms.c in libquicktime 1.2.4 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) via a crafted mp4 file.
  • CVE-2017-9124: The quicktime_match_32 function in util.c in libquicktime 1.2.4 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted mp4 file.
  • CVE-2017-9126: The quicktime_read_dref_table function in dref.c in libquicktime 1.2.4 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) via a crafted mp4 file.
  • CVE-2017-9122: The quicktime_read_moov function in moov.c in libquicktime 1.2.4 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a crafted mp4 file.
  • CVE-2017-9125: The lqt_frame_duration function in lqt_quicktime.c in libquicktime 1.2.4 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted mp4 file.
  • CVE-2017-9128: The quicktime_video_width function in lqt_quicktime.c in libquicktime 1.2.4 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted mp4 file.
Please fix them.
Created: 2017-06-12 Last update: 2018-06-02 08:03
Build log checks report 2 warnings low
Build log checks report 2 warnings
Created: 2016-04-07 Last update: 2016-04-07 19:01
news
[rss feed]
  • [2018-05-30] libquicktime 2:1.2.4-12 MIGRATED to testing (Debian testing watch)
  • [2018-05-25] Accepted libquicktime 2:1.2.4-12 (source) into unstable (James Cowgill)
  • [2017-07-28] Accepted libquicktime 2:1.2.4-3+deb7u2 (source all amd64) into oldoldstable (Thorsten Alteholz)
  • [2017-07-16] Accepted libquicktime 2:1.2.4-10+deb9u1 (source) into proposed-updates->stable-new, proposed-updates (Moritz Mühlenhoff) (signed by: Salvatore Bonaccorso)
  • [2017-07-06] libquicktime 2:1.2.4-11 MIGRATED to testing (Debian testing watch)
  • [2017-06-30] Accepted libquicktime 2:1.2.4-11 (source) into unstable (Reinhard Tartler)
  • [2017-03-09] Accepted libquicktime 2:1.2.4-7+deb8u1 (source all amd64) into proposed-updates->stable-new, proposed-updates (Balint Reczey)
  • [2017-03-05] libquicktime 2:1.2.4-10 MIGRATED to testing (Debian testing watch)
  • [2017-03-01] Accepted libquicktime 2:1.2.4-3+deb7u1 (source all amd64) into oldstable (Balint Reczey)
  • [2017-02-27] Accepted libquicktime 2:1.2.4-10 (source) into unstable (Balint Reczey)
  • [2016-12-05] libquicktime 2:1.2.4-9 MIGRATED to testing (Debian testing watch)
  • [2016-11-29] Accepted libquicktime 2:1.2.4-9 (source) into unstable (Sebastian Ramacher)
  • [2016-03-14] libquicktime 2:1.2.4-8 MIGRATED to testing (Debian testing watch)
  • [2016-03-08] Accepted libquicktime 2:1.2.4-8 (source all) into unstable (Sebastian Ramacher)
  • [2014-10-06] libquicktime 2:1.2.4-7 MIGRATED to testing (Britney)
  • [2014-09-30] Accepted libquicktime 2:1.2.4-7 (source all amd64) into unstable (Alessio Treglia)
  • [2014-05-22] libquicktime 2:1.2.4-6 MIGRATED to testing (Debian testing watch)
  • [2014-05-13] Accepted libquicktime 2:1.2.4-6 (source all amd64) (Sebastian Ramacher)
  • [2014-03-16] Accepted libquicktime 2:1.2.4-5 (source all amd64) (Reinhard Tartler)
  • [2013-06-23] libquicktime 2:1.2.4-4 MIGRATED to testing (Debian testing watch)
  • [2013-06-12] Accepted libquicktime 2:1.2.4-4 (source all i386) (Reinhard Tartler)
  • [2012-06-01] libquicktime 2:1.2.4-3 MIGRATED to testing (Debian testing watch)
  • [2012-05-21] Accepted libquicktime 2:1.2.4-3 (source all amd64) (Alessio Treglia)
  • [2012-05-03] libquicktime 2:1.2.4-2 MIGRATED to testing (Debian testing watch)
  • [2012-04-23] Accepted libquicktime 2:1.2.4-2 (source all amd64) (Alessio Treglia)
  • [2012-04-21] libquicktime 2:1.2.4-1 MIGRATED to testing (Debian testing watch)
  • [2012-04-10] Accepted libquicktime 2:1.2.4-1 (source all amd64) (Alessio Treglia)
  • [2011-08-14] libquicktime 2:1.2.3-4 MIGRATED to testing (Debian testing watch)
  • [2011-08-03] Accepted libquicktime 2:1.2.3-4 (source all amd64) (Alessio Treglia)
  • [2011-08-01] Accepted libquicktime 2:1.2.3-3 (source all amd64) (Alessio Treglia)
  • 1
  • 2
bugs [bug history graph]
  • all: 6
  • RC: 0
  • I&N: 5
  • M&W: 1
  • F&P: 0
  • patch: 0
links
  • homepage
  • lintian (0, 20)
  • buildd: logs, checks, clang, reproducibility
  • popcon
  • browse source code
  • edit tags
  • security tracker
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 2:1.2.4-12build2
  • 2 bugs

Debian Package Tracker — Copyright 2013-2018 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing