diff options
author | Reinhard Tartler <siretart@tauware.de> | 2012-01-10 22:22:05 +0100 |
---|---|---|
committer | Reinhard Tartler <siretart@tauware.de> | 2012-01-10 22:22:05 +0100 |
commit | 15df4428d264287ec1577f92296b178f86cbe14d (patch) | |
tree | cb956b5e82a3e7b28af856557ee8486af1ce3898 | |
parent | ec0124203c9bf12b926b87544ced79c8b78c75ce (diff) | |
download | ffmpeg-15df4428d264287ec1577f92296b178f86cbe14d.tar.gz |
Release notes and changelog for 0.5.7
-rw-r--r-- | Changelog | 10 | ||||
-rw-r--r-- | RELEASE | 17 |
2 files changed, 27 insertions, 0 deletions
@@ -2,6 +2,16 @@ Entries are sorted chronologically from oldest to youngest within each release, releases are sorted from youngest to oldest. +version 0.5.7: +- vorbis: An additional defense in the Vorbis codec. (CVE-2011-3895) +- vorbisdec: Fix decoding bug with channel handling. +- matroskadec: Fix a bug where a pointer was cached to an array that might + later move due to a realloc(). (CVE-2011-3893) +- vorbis: Avoid some out-of-bounds reads. (CVE-2011-3893) +- vp3: fix oob read for negative tokens and memleaks on error, (CVE-2011-3892) +- vp3: fix streams with non-zero last coefficient. + + version 0.5.6: - svq1dec: call avcodec_set_dimensions() after dimensions changed. (NGS00148, CVE-2011-4579) - vmd: fix segfaults on corruped streams (CVE-2011-4364) @@ -170,3 +170,20 @@ release. Distributors and system integrators are encouraged to update and share their patches against this branch. + + + +* 0.5.7 Jan 11, 2012 + +General notes +------------- + +This mostly maintenance-only release that addresses a number a number of +bugs such as security and compilation issues that have been brought to +our attention. Among other (rather minor) fixes, this release features +fixes for the VP3 decoder (CVE-2011-3892), vorbis decoder, and matroska +demuxer (CVE-2011-3893 and CVE-2011-3895). + +Distributors and system integrators are encouraged +to update and share their patches against this branch. For a full list +of changes please see the Changelog file. |