faad2 (2.6.1-2ubuntu0.1) hardy-security; urgency=low * SECURITY UPDATE: Heap-based buffer overflow in the decodeMP4file function (frontend/main.c) in FAAD2 before 2.6.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted MPEG-4 (MP4) file. (Closes LP: #277110) * 12_heap_overflow.dpatch - Patch supplied by upstream to address vulnerability. * References http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-4201 http://www.audiocoding.com/patch/main_overflow.diff CVE-2008-4201 -- Stefan Lesicnik Thu, 02 Oct 2008 16:26:26 +0200 faad2 (2.6.1-2) unstable; urgency=low * Remove XMMS plugin as XMMS is being removed (Closes: #456724) -- Matthew W. S. Bell Fri, 21 Dec 2007 00:04:17 +0000 faad2 (2.6.1-1) unstable; urgency=low * Import new upstream version containing new license text (Closes: #451948) * Change build system to call autoreconf at build time, as upstream no longer ships generated files * Update debian/copyright to reflect new license text * Remove Build-Depends on libsndfile1-dev (Closes: #452362) -- Matthew W. S. Bell Wed, 28 Nov 2007 23:45:05 +0000 faad2 (2.6-1) unstable; urgency=low * Import new 2.6 release. Includes several small off-by-one scale fixes. * Update the copyright as new code includes a clarification of the license text, which indicates that the entire work is under the GPLv2 (closes: #419339). -- Matthew W. S. Bell Mon, 15 Oct 2007 00:16:21 +0100 faad2 (2.5-5) unstable; urgency=low * Make packages depends bin-NMU safe -- Matthew W. S. Bell Fri, 17 Aug 2007 16:07:59 +0100 faad2 (2.5-4) unstable; urgency=low * Add mp4ff headers to libfaad-dev package (Closes: 409648) -- Matthew W. S. Bell Fri, 11 May 2007 19:44:22 +0100 faad2 (2.5-3) unstable; urgency=low * Add patch to stabilise/sanitise headers (Closes: 404279) * Port several fixes from Ubuntu * Add an mp4ff static library -- Matthew W. S. Bell Sun, 15 Apr 2007 04:23:35 +0100 faad2 (2.5-2) unstable; urgency=low * add xmms-mp4 desription read not like nonsense (Closes: #399457) * Compile without Digital Radio Mondiale support, as it breaks base functionality * Update debian/copyright (See: #403117) -- Matthew W. S. Bell Mon, 4 Dec 2006 19:56:22 +0000 faad2 (2.5-1) unstable; urgency=low * Call make install with DESTDIR instead of prefix * Change configure/Makefile to provide xmms config differently * Add manual page for faad utility * Call make uninstall in clean * Add dummy libfaad2-0 pacakge to satisfy some third-party dependencies * Upload into main (Closes: #306366) -- Matthew W. S. Bell Wed, 18 Oct 2006 23:41:32 +0100 faad2 (2.5-0.0) unstable; urgency=low * New upstream release. * Add drm (Digital Radio Mondiale) support. -- Christian Marillat Wed, 6 Sep 2006 20:18:25 +0200 faad2 (2.0.0+cvs20060416-0.1) unstable; urgency=low * Rebuild for amd64. -- Christian Marillat Sat, 13 May 2006 08:58:34 +0200 faad2 (2.0.0+cvs20060416-0.0) unstable; urgency=low * CVS release. -- Christian Marillat Sun, 16 Apr 2006 17:15:00 +0200 faad2 (2.0.0-0.7) unstable; urgency=low * Rebuild for gcc 4.0 -- Christian Marillat Sat, 16 Jul 2005 17:34:28 +0200 faad2 (2.0.0-0.6) unstable; urgency=low * New patch from Gentoo to fix amd64 problem with some files. Thanks to Carl Schneidinger. -- Christian Marillat Fri, 20 May 2005 18:42:23 +0200 faad2 (2.0.0-0.5) unstable; urgency=low * Apply patch from Arnaud Rouanet to fix the -w option in faad. -- Christian Marillat Mon, 21 Mar 2005 10:13:05 +0100 faad2 (2.0.0-0.4) unstable; urgency=low * New patch 04_mp4ff.h to replace "mp4ff_int_types.h" include by -- Christian Marillat Wed, 9 Mar 2005 08:59:35 +0100 faad2 (2.0.0-0.3) unstable; urgency=low * Add libfaac-dev in Build-Depends. * Little hack to not build the mpeg4ip plugin. -- Christian Marillat Wed, 26 Jan 2005 07:36:25 +0100 faad2 (2.0.0-0.2) unstable; urgency=low * Build with libmp4 * Add new package xmms-mp4 -- Christian Marillat Mon, 25 Oct 2004 10:19:52 +0200 faad2 (2.0.0-0.1) unstable; urgency=low * Really apply my patch to link against -lm -- Christian Marillat Thu, 29 Jul 2004 15:48:22 +0200 faad2 (2.0.0-0.0) unstable; urgency=low * New upstream release. -- Christian Marillat Sun, 4 Jul 2004 00:26:23 +0200 faad2 (2.0-rc3-0.0) unstable; urgency=low * New upstream release. -- Christian Marillat Tue, 9 Dec 2003 10:57:01 +0100 faad2 (1.1-0.0) unstable; urgency=low * Initial Release. -- Christian Marillat Sun, 29 Dec 2002 23:09:33 +0100