[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Bug#889892: marked as done (mpv: fix for CVE-2018-6360 breaks youtube playlists)



Your message dated Sat, 10 Feb 2018 21:03:08 +0000
with message-id <E1ekcIe-000BvC-70@fasolo.debian.org>
and subject line Bug#889892: fixed in mpv 0.23.0-2+deb9u2
has caused the Debian Bug report #889892,
regarding mpv: fix for CVE-2018-6360 breaks youtube playlists
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact owner@bugs.debian.org
immediately.)


-- 
889892: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=889892
Debian Bug Tracking System
Contact owner@bugs.debian.org with problems
--- Begin Message ---
Source: mpv
Version: 0.23.0-1
Severity: grave
Tags: security upstream
Forwarded: https://github.com/mpv-player/mpv/issues/5456

Hi,

the following vulnerability was published for mpv.

CVE-2018-6360[0]:
| mpv through 0.28.0 allows remote attackers to execute arbitrary code
| via a crafted web site, because it reads HTML documents containing
| VIDEO elements, and accepts arbitrary URLs in a src attribute without a
| protocol whitelist in player/lua/ytdl_hook.lua. For example, an
| av://lavfi:ladspa=file= URL signifies that the product should call
| dlopen on a shared object file located at an arbitrary local pathname.
| The issue exists because the product does not consider that youtube-dl
| can provide a potentially unsafe URL.

If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2018-6360
    https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-6360
[1] https://github.com/mpv-player/mpv/issues/5456

Regards,
Salvatore

--- End Message ---
--- Begin Message ---
Source: mpv
Source-Version: 0.23.0-2+deb9u2

We believe that the bug you reported is fixed in the latest version of
mpv, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 889892@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
James Cowgill <jcowgill@debian.org> (supplier of updated mpv package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

Format: 1.8
Date: Thu, 08 Feb 2018 12:27:06 +0000
Source: mpv
Binary: mpv libmpv1 libmpv-dev mplayer2
Architecture: source amd64 all
Version: 0.23.0-2+deb9u2
Distribution: stretch-security
Urgency: high
Maintainer: Debian Multimedia Maintainers <pkg-multimedia-maintainers@lists.alioth.debian.org>
Changed-By: James Cowgill <jcowgill@debian.org>
Description:
 libmpv-dev - video player based on MPlayer/mplayer2 (client library dev files)
 libmpv1    - video player based on MPlayer/mplayer2 (client library)
 mplayer2   - transitional dummy package for mpv
 mpv        - video player based on MPlayer/mplayer2
Closes: 889892
Changes:
 mpv (0.23.0-2+deb9u2) stretch-security; urgency=high
 .
   * debian/patches/08_ytdl-hook-whitelist-protocols.patch:
     - Fix regression in CVE-2018-6360 patch which broke youtube playlists.
       (Closes: #889892)
Checksums-Sha1:
 483e70e1d85c2895c2c313dc0b6e2d393b08312b 2935 mpv_0.23.0-2+deb9u2.dsc
 7198c199b83903b2f0882db831c429099f463c36 101984 mpv_0.23.0-2+deb9u2.debian.tar.xz
 a34037a092be88db83fa046f4d64035c92ba238d 67938 libmpv-dev_0.23.0-2+deb9u2_amd64.deb
 8090d05e7674bfbf67aa66c85bcc0f3103ad1483 2379788 libmpv1-dbgsym_0.23.0-2+deb9u2_amd64.deb
 0103fb8c4f15762baa982e428fb6e40f45fc11ec 670790 libmpv1_0.23.0-2+deb9u2_amd64.deb
 4a141b81accd3086bcb8dc7dc9776f6b10a16172 40636 mplayer2_0.23.0-2+deb9u2_all.deb
 02950e329c4d94a7621b52d0e9013eb7086d8980 2396602 mpv-dbgsym_0.23.0-2+deb9u2_amd64.deb
 48fb408c14ef98bd0692d69c676f4b2166e3e20e 17176 mpv_0.23.0-2+deb9u2_amd64.buildinfo
 28487b4ecc25c687f2210d5c3be1657f5d157d95 875884 mpv_0.23.0-2+deb9u2_amd64.deb
Checksums-Sha256:
 db8732bd7c711890682c431eaa80bc0f48e13e609c87add7e2e255595684c5b9 2935 mpv_0.23.0-2+deb9u2.dsc
 e3458e1a8cad0edcd0488d6f3281940cde3ffa9d3e77ba13561a7121f12b8e5a 101984 mpv_0.23.0-2+deb9u2.debian.tar.xz
 ec0a730e0769d5070f34e9421d13d4d448cffba17200407fc2107d8767deb015 67938 libmpv-dev_0.23.0-2+deb9u2_amd64.deb
 6a5f0e9ab2fb86d2fd08fd10f88905968343327cf8321ba249798492f3f995f0 2379788 libmpv1-dbgsym_0.23.0-2+deb9u2_amd64.deb
 e0a32ce4807d641b1ec4096ea710c885995d5cb27ea895897800a3ef7a42927e 670790 libmpv1_0.23.0-2+deb9u2_amd64.deb
 ff5e5071f88dec2ffc566089e0ffab21f63fd34e489bf0803aba55646dbb4d7c 40636 mplayer2_0.23.0-2+deb9u2_all.deb
 58312f0dcd864ee45c21362b607f3292a4236836d238ee321764b3a932ea88a9 2396602 mpv-dbgsym_0.23.0-2+deb9u2_amd64.deb
 383d7a74e7a885f368c87e4874d14a2de1297fac1896c097fe0f0296e9e38308 17176 mpv_0.23.0-2+deb9u2_amd64.buildinfo
 d992bb4a1cbaed416e3156a9a3dcf0a60aa7e1369d4bd6ae6146aa24f44fabcd 875884 mpv_0.23.0-2+deb9u2_amd64.deb
Files:
 10d6842963e381adeb8b3547ff498e46 2935 video optional mpv_0.23.0-2+deb9u2.dsc
 0e09c928a9567fb8f3f69d842ad26e24 101984 video optional mpv_0.23.0-2+deb9u2.debian.tar.xz
 14425412d59ef9a5e4b143e3f9117ea1 67938 libdevel optional libmpv-dev_0.23.0-2+deb9u2_amd64.deb
 1a586f92197da69ebf115f47cb30b9ad 2379788 debug extra libmpv1-dbgsym_0.23.0-2+deb9u2_amd64.deb
 e6bce029fae1bc57cf237a8b383968f5 670790 libs optional libmpv1_0.23.0-2+deb9u2_amd64.deb
 14f50f7b3325de2375a442020442e342 40636 oldlibs optional mplayer2_0.23.0-2+deb9u2_all.deb
 ea5060e776b57a7ba073584c49412a91 2396602 debug extra mpv-dbgsym_0.23.0-2+deb9u2_amd64.deb
 ee33a20ea1277b377f54181856d74c85 17176 video optional mpv_0.23.0-2+deb9u2_amd64.buildinfo
 3f9e619bd095bb477cbe0743acf16add 875884 video optional mpv_0.23.0-2+deb9u2_amd64.deb

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCAAdFiEEayzFlnvRveqeWJspbsLe9o/+N3QFAlp84kEACgkQbsLe9o/+
N3SB3Q/+PKlOl24Rsfd0UWKUZevw/AdPFnc2wFKM4HmOYOdX5Gg73yWUQdrKYnr6
zYokeVcyzr5guxSQblzUY4V1AsSLfOjP81xEzBRtnTnx+fH4aqJd4H2C6zNcYdRp
FOl6i04qlBfSNlDy40cqwoIaZF9tyT8skDOu5j0yrh6k+VIdb+p4P3/7jJ6Ce25n
yv5RO83b/kirfZfUvx4SOwDuMIELatH2t7FP3zs6XecW58tpDHzVsISMJlHvR7FY
OB8Pt/VsBzTemh9NFFoGFFFGVdKvaH6Yq56GOdZgI0050KSgZodWzdmuCeF1DDdJ
Qfn4Prw5L876S7eKf9w343g278s0wjT0uanIQmaBH11m3e4bTPK8VstLR/tbILW2
Kpj3gLfR/23Dny7vOsk0MVMIFSCfuvB22txtjcBDH6xVV0zAwAPCJ77HcJpFdQVx
zxjjsknVljc6B2wNJ9gP3MNTr56FOjl7uFcJ++ZSFOpC9gOHVPZk+VVYy3lb7pDJ
D4Gv0Xn5xxySzI3fYhLDVc4pqyzG23HIsWCo0Ban7k7XUBy/B3lzPOaEJkizH4qS
tPy7VSED7eKappLKykDsoxEKXOVi3iNqhSgHjjZVpADCmEMGq1znKknqfjQNz1Wd
dlHvoKut325DVG7/fLgHrkvW/Lj06fIFuVXVbokKljFkK+5j6eg=
=cXSn
-----END PGP SIGNATURE-----

--- End Message ---

Reply to: