Bug#572950: libtheora: multiple vulnerabilities in lenny

Michael Gilbert michael.s.gilbert at gmail.com
Sun Mar 7 19:51:06 UTC 2010


package: libtheora
version: 1.0~beta3-1
severity: serious
tags: security

Hi,

I have prepared a lenny package for the theora issues that are
were recently addressed in xulrunner. Note that two of them never got a
CVE (one should probably be requested), but have been fixed ever since
the first release of firefox 3.5. The package is at
http://alioth.debian.org/~gilbert-guest/libtheora and the debdiff is
attached.

These issues are already fixed in unstable.  Please coordinate with the
security team to release a DSA for lenny.

Thanks,
Mike
-------------- next part --------------
A non-text attachment was scrubbed...
Name: libtheora-lenny.debdiff
Type: application/octet-stream
Size: 9451 bytes
Desc: not available
URL: <http://lists.alioth.debian.org/pipermail/pkg-xiph-maint/attachments/20100307/94bc9876/attachment.obj>


More information about the pkg-xiph-maint mailing list