LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Slackware
User Name
Password
Slackware This Forum is for the discussion of Slackware Linux.

Notices


Reply
  Search this Thread
Old 04-01-2008, 12:50 PM   #1
shadowsnipes
Senior Member
 
Registered: Sep 2005
Distribution: Slackware
Posts: 1,443

Rep: Reputation: 73
xine-lib-1.1.11.1 security update change???


A day or two ago I upgraded xine-lib with the
xine-lib-1.1.11-i686-1_slack12.0.tgz security update with
md5sum 04dfd67cfc12258f05b2e01612494572

Today I received another notification that a security update for this was available. The file name is the same but
md5sum c883b1ebae2955f6d8f289e9e80cf7b2

What is going on here? The slackware.com website still shows the old md5sum, but it has indeed been changed on ftp.slackware.com.
 
Old 04-01-2008, 12:57 PM   #2
Jeebizz
Senior Member
 
Registered: May 2004
Distribution: Slackware15.0 64-Bit Desktop, Debian 11 non-free Toshiba Satellite Notebook
Posts: 4,186

Rep: Reputation: 1379Reputation: 1379Reputation: 1379Reputation: 1379Reputation: 1379Reputation: 1379Reputation: 1379Reputation: 1379Reputation: 1379Reputation: 1379
If you received an update, I would imagine that there would also be an explanation of the second version of that file.

From today's changelog:
Quote:
Tue Apr 1 02:41:32 CDT 2008
...
xap/xine-lib-1.1.11.1-i686-1.tgz: Earlier versions of xine-lib suffer from an
integer overflow which may lead to a buffer overflow that could potentially
be used to gain unauthorized access to the machine if a malicious media
file is played back. File types affected this time include .flv, .mov, .rm,
.mve, .mkv, and .cak.
For more information on this security issue, please see:
http://cve.mitre.org/cgi-bin/cvename...=CVE-2008-1482
(* Security fix *)
...

Woo! my 666th post, yea!! \o/\o/
 
Old 04-01-2008, 01:16 PM   #3
H_TeXMeX_H
LQ Guru
 
Registered: Oct 2005
Location: $RANDOM
Distribution: slackware64
Posts: 12,928
Blog Entries: 2

Rep: Reputation: 1301Reputation: 1301Reputation: 1301Reputation: 1301Reputation: 1301Reputation: 1301Reputation: 1301Reputation: 1301Reputation: 1301Reputation: 1301
Quick, throw salt over your shoulder ... no, wait, that's for something else isn't it ?
 
Old 04-01-2008, 01:23 PM   #4
shadowsnipes
Senior Member
 
Registered: Sep 2005
Distribution: Slackware
Posts: 1,443

Original Poster
Rep: Reputation: 73
Normally, I wouldn't be confused, but this update was just put out a day or two ago

Code:
Mon Mar 31 23:33:58 CDT 2008
xap/xine-lib-1.1.11.1-i686-1_slack12.0.tgz:
  Upgraded to xine-lib-1.1.11.1.
  Earlier versions of xine-lib suffer from an integer overflow which may lead
  to a buffer overflow that could potentially be used to gain unauthorized
  access to the machine if a malicious media file is played back.  File types
  affected this time include .flv, .mov, .rm, .mve, .mkv, and .cak.
  For more information on this security issue, please see:
    http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1482
  (* Security fix *)
+--------------------------+
Sat Mar 29 03:09:17 CDT 2008
.
.
.
patches/packages/xine-lib-1.1.11-i686-1_slack12.0.tgz:
  Earlier versions of xine-lib suffer from an array index bug that
  may have security implications if a malicious RTSP stream is
  played.  Playback of other media formats is not affected.
  If you use RTSP, you should probably upgrade xine-lib.
  For more information on the security issue, please see:
    http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0073
  (* Security fix *)
I guess what I don't understand is why wasn't there a note that it was updated again (to avoid confusion) or why didn't the build number at least change.

I suppose the build number didn't change because the build script might be exactly the same. But then the source should be different so you would think the version number would be different.

Ahh, the security advisory just got updated on slackware.com. All is well
 
Old 04-01-2008, 02:13 PM   #5
brianL
LQ 5k Club
 
Registered: Jan 2006
Location: Oldham, Lancs, England
Distribution: Slackware64 15; SlackwareARM-current (aarch64); Debian 12
Posts: 8,298
Blog Entries: 61

Rep: Reputation: Disabled
Quote:
Originally Posted by Jeebizz View Post
Woo! my 666th post, yea!! \o/\o/
Jeebizz is the Antichrist!!!
 
Old 04-01-2008, 02:21 PM   #6
shadowsnipes
Senior Member
 
Registered: Sep 2005
Distribution: Slackware
Posts: 1,443

Original Poster
Rep: Reputation: 73
I apparently need to start getting more rest....the version number is slightly different.

April fools on me!!!
 
Old 04-01-2008, 02:56 PM   #7
T3slider
Senior Member
 
Registered: Jul 2007
Distribution: Slackware64-14.1
Posts: 2,367

Rep: Reputation: 843Reputation: 843Reputation: 843Reputation: 843Reputation: 843Reputation: 843Reputation: 843
Darn it, I forgot it was April fools' day. I guess it's too late to get out the Whoopee cushion. (And yes, the version number is slightly different, with an extra .1)
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
LXer: Debian update for xine-lib LXer Syndicated Linux News 0 07-07-2006 11:54 PM
xine gui install doesn't find xine-lib blackdragonblood Linux - Software 5 02-10-2006 06:19 PM
compatability between xine lib and xine ui b0nd Linux - Newbie 1 01-30-2005 06:13 AM
problem after update xine-lib salahuddin_66 Slackware 2 06-08-2004 08:28 PM
xine.de is under construction - how to install - xine-lib-1-rc3a.tar.gz sanjaya Linux - Software 1 02-13-2004 08:36 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Slackware

All times are GMT -5. The time now is 10:22 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration