Please read this before reporting a bug:
https://wiki.archlinux.org/title/Bug_reporting_guidelines
Do NOT report bugs when a package is just outdated, or it is in the AUR. Use the 'flag out of date' link on the package page, or the Mailing List.
REPEAT: Do NOT report bugs for outdated packages!
https://wiki.archlinux.org/title/Bug_reporting_guidelines
Do NOT report bugs when a package is just outdated, or it is in the AUR. Use the 'flag out of date' link on the package page, or the Mailing List.
REPEAT: Do NOT report bugs for outdated packages!
FS#7914 - security issues in mplayer-1.0rc1
Attached to Project:
Arch Linux
Opened by Nicolai Lissner (blackpenguin) - Thursday, 30 August 2007, 16:47 GMT
Last edited by Dan McGee (toofishes) - Thursday, 06 September 2007, 03:28 GMT
Opened by Nicolai Lissner (blackpenguin) - Thursday, 30 August 2007, 16:47 GMT
Last edited by Dan McGee (toofishes) - Thursday, 06 September 2007, 03:28 GMT
|
DetailsDescription:
I noticed archlinux's mplayer does not fix the cddb-issue (arbitrary remote code execution under the user ID running the player!) announced in June. Please fix this. Additional info: http://www.mplayerhq.hu/design7/news.html |
This task depends upon
Closed by Dan McGee (toofishes)
Thursday, 06 September 2007, 03:28 GMT
Reason for closing: Not a bug
Additional comments about closing: already fixed
Thursday, 06 September 2007, 03:28 GMT
Reason for closing: Not a bug
Additional comments about closing: already fixed
Comment by Dan McGee (toofishes) -
Thursday, 06 September 2007, 01:49 GMT
This looks like it is fixed in the PKGBUILD to me...take a look at the sources array.
Comment by Nicolai Lissner (blackpenguin) -
Thursday, 06 September 2007, 02:14 GMT
oops. true. false alarm then. I probably examined only the patches in cvs only. Sorry about the noise :>