Browse Source

Release notes and changelog for 0.5.7

tags/n0.5.8
Reinhard Tartler 14 years ago
parent
commit
15df4428d2
2 changed files with 27 additions and 0 deletions
  1. +10
    -0
      Changelog
  2. +17
    -0
      RELEASE

+ 10
- 0
Changelog View File

@@ -2,6 +2,16 @@ Entries are sorted chronologically from oldest to youngest within each release,
releases are sorted from youngest to oldest.


version 0.5.7:
- vorbis: An additional defense in the Vorbis codec. (CVE-2011-3895)
- vorbisdec: Fix decoding bug with channel handling.
- matroskadec: Fix a bug where a pointer was cached to an array that might
later move due to a realloc(). (CVE-2011-3893)
- vorbis: Avoid some out-of-bounds reads. (CVE-2011-3893)
- vp3: fix oob read for negative tokens and memleaks on error, (CVE-2011-3892)
- vp3: fix streams with non-zero last coefficient.


version 0.5.6:
- svq1dec: call avcodec_set_dimensions() after dimensions changed. (NGS00148, CVE-2011-4579)
- vmd: fix segfaults on corruped streams (CVE-2011-4364)


+ 17
- 0
RELEASE View File

@@ -170,3 +170,20 @@ release.

Distributors and system integrators are encouraged to update and share
their patches against this branch.



* 0.5.7 Jan 11, 2012

General notes
-------------

This mostly maintenance-only release that addresses a number a number of
bugs such as security and compilation issues that have been brought to
our attention. Among other (rather minor) fixes, this release features
fixes for the VP3 decoder (CVE-2011-3892), vorbis decoder, and matroska
demuxer (CVE-2011-3893 and CVE-2011-3895).

Distributors and system integrators are encouraged
to update and share their patches against this branch. For a full list
of changes please see the Changelog file.

Loading…
Cancel
Save