mplayer

Postate qui se avete consigli per migliorare i pacchetti disponibili in questo sito o se avete problemi con installazione, funzionamento o altro.

Moderatore: Staff

Regole del forum
1) Citare in modo preciso il nome del pacchetto.
2) Specificare se discussione/suggerimento o richiesta d'aiuto.
3) Leggere attentamente le risposte ricevute
4) Scrivere i messaggi con il colore di default, evitare altri colori.
5) Scrivere in Italiano o in Inglese, se possibile grammaticalmente corretto, evitate stili di scrittura poco chiari, quindi nessuna abbreviazione tipo telegramma o scrittura stile SMS o CHAT.
6) Appena registrati è consigliato presentarsi nel forum dedicato.

La non osservanza delle regole porta a provvedimenti di vari tipo da parte dello staff, in particolare la non osservanza della regola 5 porta alla cancellazione del post e alla segnalazione dell'utente. In caso di recidività l'utente rischia il ban temporaneo.
Rispondi
samiel
Staff
Staff
Messaggi: 5511
Iscritto il: ven 16 gen 2004, 0:00
Nome Cognome: Mauro Sacchetto
Slackware: 13.0
Kernel: 2.26
Desktop: KDE
Distribuzione: anche Debian
Località: Venezia

mplayer

Messaggio da samiel »

Nel sito ho trovato la versione try2.
Dove avete recuperato la try3?

Grazie
M.

Avatar utente
albatros
Iper Master
Iper Master
Messaggi: 2098
Iscritto il: sab 4 feb 2006, 13:59
Kernel: 6.18.0
Desktop: gnome and lxqt
Distribuzione: Ubuntu 24.04 & FC 41
Località: Darmstadt - Germania

Messaggio da albatros »

La try3 è praticamente la try2 con una patch che corregge un'heap overflow...
Non so se successivamente sia stata messa da qualche parte una try3 già pronta all'uso, penso che però i packager abbiano seguito semplicemente le indicazioni all'ultima riga del seguente annuncio, presente su http://www.mplayerhq.hu/design7/news.html:
2006.02.15, Wednesday :: heap overflow in demuxer.h
posted by Roberto
Summary

A potential buffer overflow was found in the ASF demuxer, and further analysis showed that the bug was in some more generic code in demuxer.h, used to create and resize buffers. You can read the original bug report here media-video/mplayer ASF File Parsing Integer Overflow (CAN-2006-0579) on Gentoo Bugzilla.
Severity

High (arbitrary remote code execution under the user ID running the player) when streaming an ASF file from a malicious server, medium (local code execution under the user ID running the player) if you play a malicious ASF file locally. At the time the buffer overflow was fixed there was no known exploit.
Solution

A fix for this problem was committed to CVS on Sun Feb 12 09:28:09 2006 UTC, and enhanced in versions 1.89 and 1.90. Users of affected MPlayer versions should download a patch for MPlayer 1.0pre7try2 here or here or update to the latest version if they're using CVS.

Please note that we are not releasing an updated tarball with this fix at this moment. Since MPlayer 1.0pre7 is very old, we encourage you to upgrade to the CVS version.
If you need to stay with 1.0pre7, get the MPlayer 1.0pre7try2 tarball, apply the patch with the fix and recompile MPlayer.
If you mantain a binary package for MPlayer, please name the updated version MPlayer 1.0pre7try3.

samiel
Staff
Staff
Messaggi: 5511
Iscritto il: ven 16 gen 2004, 0:00
Nome Cognome: Mauro Sacchetto
Slackware: 13.0
Kernel: 2.26
Desktop: KDE
Distribuzione: anche Debian
Località: Venezia

Messaggio da samiel »

Mi era del tutto sfuggita quella parte
Mille grazie
E comunque ssperiamo esca una nuova release
prima o poi...

M.

Rispondi