[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

[SECURITY] [DLA 3358-1] mpv security update



-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

- -------------------------------------------------------------------------
Debian LTS Advisory DLA-3358-1                debian-lts@lists.debian.org
https://www.debian.org/lts/security/                    Thorsten Alteholz
March 12, 2023                                https://wiki.debian.org/LTS
- -------------------------------------------------------------------------

Package        : mpv
Version        : 0.29.1-1+deb10u1
CVE ID         : CVE-2020-19824


An issue has been found in mpv, a video player based on MPlayer/mplayer2.
Due to a use after free an attacker coudl execute arbitrary code or crash the program via the ao_c parameter.


For Debian 10 buster, this problem has been fixed in version
0.29.1-1+deb10u1.

We recommend that you upgrade your mpv packages.

For the detailed security status of mpv please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/mpv

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS

-----BEGIN PGP SIGNATURE-----

iQKTBAEBCgB9FiEEYgH7/9u94Hgi6ruWlvysDTh7WEcFAmQND3VfFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDYy
MDFGQkZGREJCREUwNzgyMkVBQkI5Njk2RkNBQzBEMzg3QjU4NDcACgkQlvysDTh7
WEfUlw//UFe7nWnI8mftPyR1a8PrLulzZbdUomsbE1sNI38j4bma4a/1gbOjJ+2S
kbQ5im3+A3lWBUNqPL+5YxKZBegfilzEZucNQcca1YgZpLfXem7f+8Gqk/PFh0qX
m+Znbeon3WSmQxhpYyrV7E/ZKA6NNqNAs7oR1AQEzkioQGfcFQ7k8hgM/yOU+iCo
iwMgVi1aGhccAJbe/FSXQRe1YzVhQkpBqSvtN6eOjxxcJ9iGD/bJURfbtw/2Ah9M
ztdL5K2eGmxt7C86+cNo+/Rpfr8fas6FWCohhlnpMGRYspnnzk3sXpdA7rSKVQRd
j0eKxNzfroZM0n1F4dUkcY4EWEcgfL60+Avc4KREF5N8sLcJyXkDj35EckFkGizy
CsBm3VKVU8c5OK2ggPJThHc0EfFVujrzhTYW2jcxROlSTw3DiYDnh7CLK8AEP/Jm
+E088BcjXZsy29E4f+agKc6PqAAD5GalTT84JJ9DeamUtpiCv5n0UbpU0CGoWz5X
2oCv1NJZUpuVq0pOyg8Cxc/M4D0Cu2i6JzeziBZXREQYcy60bNpp5OG2nmzmbtTT
DLq4qfFGxwutuAfTBZ5E18C6qVEP26Sn2rR4pmncAKvd7YE0mrv8HKTViO4e77n5
Ijs4Nn96ebeXComLDLFXzaUX9BDBr7Dkdva+qzvJThI4sj1/eek=
=CTfA
-----END PGP SIGNATURE-----


Reply to: