From Mageia wiki
Jump to: navigation, search

MGASA-2012-0199

Date: August 6th, 2012
Affected releases: 1


Description:
Updated blender package fixes security vulnerabilities:

dpcm: ignore extra unpaired bytes in stereo streams (CVE-2011-3951)

h264: Add check for invalid chroma_format_idc (CVE-2012-0851)

adpcm: ADPCM Electronic Arts has always two channels (CVE-2012-0852)

kmvc: Check palsize (CVE-2011-3952)

Blender's internal copy of ffmpeg has been updated to 0.5.10 to fix
these issues, as well as some other bugs.


Updated Packages:
blender-2.49b-11.3.mga1


References:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3951
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0850
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0851
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0852
https://bugs.mageia.org/show_bug.cgi?id=6485