UbuntuUpdates.org

Package "mp3gain"

Name: mp3gain

Description:

Lossless mp3 normalizer with statistical analysis

Latest version: 1.5.2-r2-6
Release: trusty (14.04)
Level: base
Repository: universe
Homepage: http://mp3gain.sourceforge.net/

Links


Download "mp3gain"


Other versions of "mp3gain" in Trusty

No other version of this package is available in the Trusty release.

Changelog

Version: 1.5.2-r2-6 2014-03-20 17:07:24 UTC

  mp3gain (1.5.2-r2-6) unstable; urgency=high

  * Add various patches from Daniel Kobras' mpg123 packaging to fix
    buffer overflows in the embedded copy/fork of mpglib
    - CVE-2003-0577 (originally #201698 in mpg123)
    - CVE-2004-0805 (originally #270542 in mpg123)
    - CVE-2004-0991
    - CVE-2006-1655 (originally #361863 in mpg123)
    (Closes: #740268, hopefully)
  * debian/patches/*.diff: adjust so gbp-pq can import all of them
  * debian/patches/*.diff: update Sourceforge bug URLs to new layout
    (but keep the old versions for posterity)

 -- Simon McVittie <email address hidden> Wed, 19 Mar 2014 09:24:09 +0000

740268 mp3gain: A malformed mp3 file allows arbitrary code execution - Debian Bug report logs
CVE-2003-0577 mpg123 0.59r allows remote attackers to cause a denial of service and ...
CVE-2004-0805 Buffer overflow in layer2.c in mpg123 0.59r and possibly mpg123 0.59s ...
CVE-2004-0991 Buffer overflow in mpg123 before 0.59s-r9 allows remote attackers to ...
CVE-2006-1655 Multiple buffer overflows in mpg123 0.59r allow user-assisted ...



About   -   Send Feedback to @ubuntu_updates