• [gentoo-announce] [ GLSA 202405-09 ] MediaInfo, MediaInfoLib: Multiple

    From [email protected]@21:1/5 to All on Sat May 4 11:30:01 2024
    - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
    Gentoo Linux Security Advisory GLSA 202405-09
    - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
    https://security.gentoo.org/
    - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

    Severity: Normal
    Title: MediaInfo, MediaInfoLib: Multiple Vulnerabilities
    Date: May 04, 2024
    Bugs: #778992, #836564, #875374, #917612
    ID: 202405-09

    - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

    Synopsis
    ========

    Multiple vulnerabilities have been found in MediaInfo and MediaInfoLib,
    the worst of which could allow user-assisted remote code execution.

    Background
    ==========

    MediaInfo supplies technical and tag information about media files. MediaInfoLib contains MediaInfo libraries.

    Affected packages
    =================

    Package Vulnerable Unaffected
    ----------------------- ------------ ------------
    media-libs/libmediainfo < 23.10 >= 23.10
    media-video/mediainfo < 23.10 >= 23.10

    Description
    ===========

    Multiple vulnerabilities have been discovered in MediaInfo and
    MediaInfoLib. Please review the CVE identifiers referenced below for
    details.

    Impact
    ======

    Please review the referenced CVE identifiers for details.

    Workaround
    ==========

    There is no known workaround at this time.

    Resolution
    ==========

    All MediaInfo users should upgrade to the latest version:

    # emerge --sync
    # emerge --ask --oneshot --verbose ">=media-video/mediainfo-23.10"

    All MediaInfolib users should upgrade to the latest version:

    # emerge --sync
    # emerge --ask --oneshot --verbose ">=media-libs/libmediainfo-23.10"

    References
    ==========


    Availability
    ============

    This GLSA and any updates to it are available for viewing at
    the Gentoo Security Website:

    https://security.gentoo.org/glsa/202405-09

    Concerns?
    =========

    Security is a primary focus of Gentoo Linux and ensuring the
    confidentiality and security of our users' machines is of utmost
    importance to us. Any security concerns should be addressed to [email protected] or alternatively, you may file a bug at https://bugs.gentoo.org.

    License
    =======

    Copyright 2024 Gentoo Foundation, Inc; referenced text
    belongs to its owner(s).

    The contents of this document are licensed under the
    Creative Commons - Attribution / Share Alike license.

    https://creativecommons.org/licenses/by-sa/2.5
    -----BEGIN PGP SIGNATURE-----

    iQIzBAEBCgAdFiEEpqTA6ABLMxh/aChGFMQkOaVy+9kFAmY1/8MACgkQFMQkOaVy +9nF/RAAt39a5GNgK69nRGtNfcyR2hrkmrFfpBKH9En+mbkWnWEaIKmZzIuz6gHe RUDM2JdydOh6lMDSnr/oMSH70F2UgfKKgGdh/ymuxsMZb6vNLwGE14UjPayc5/Kk zNvi5RPt/7xGd4S5aQFbgBsBKW7jPCkk0/V2V0TuzJiJIeN6j31uuiwR7bjdb/3P vlCjk3pt/dlHJp/kNAUmWMtqh5oCQ3T8rl7PjENt15JLSXIrNhucxhUhWbTPswzk ZEs4iiVs82qyOK9nDkcuBjSxDIB31nJr3SMzEeCyIcT9quaiHboUiZOb0UkDoQU+ YuYNg5KroQkAlxsJIARlB4YZUbkkhOHn76TSrQtCosrEYhQQGmoP0Fsq/59rhgYO NgxaDCwsLDNtnkb8GkwZypyHBA0KFdwaLbZ6VBOZyzS2wVDq/63+jDLCpiTK8ll5 vXnaPHdBbLc0UhOMAN+w0cwyDvnLE5WU8zrwVLupMVo9mNzQLUEmO5hepUCL6ziY s5r6nAtZGd6+2/ytN8l/ZmsUxGipoh+pFMCANTYMge201oGY/cQcClYh1OSHRnM+ Rr+D+QfVnDRjaXEw+gfcqLnpOTDcD0kxeuIPrTm9PPV+5bAlM+9BoWnUB6YN+Ipy tAo7hd1Cmg7SOUW1OiQpy/ejrgzM9g7jo7bUSy+qDaW54EWh9lw=
    =zjTh
    -----END PGP SIGNATURE-----

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)