Your message dated Sat, 10 Feb 2018 21:03:08 +0000
with message-id <e1ekcie-000bvc...@fasolo.debian.org>
and subject line Bug#889892: fixed in mpv 0.23.0-2+deb9u2
has caused the Debian Bug report #889892,
regarding mpv: fix for CVE-2018-6360 breaks youtube playlists
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact ow...@bugs.debian.org
immediately.)
--
889892: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=889892
Debian Bug Tracking System
Contact ow...@bugs.debian.org with problems
--- Begin Message ---
Source: mpv
Version: 0.23.0-1
Severity: grave
Tags: security upstream
Forwarded: https://github.com/mpv-player/mpv/issues/5456
Hi,
the following vulnerability was published for mpv.
CVE-2018-6360[0]:
| mpv through 0.28.0 allows remote attackers to execute arbitrary code
| via a crafted web site, because it reads HTML documents containing
| VIDEO elements, and accepts arbitrary URLs in a src attribute without a
| protocol whitelist in player/lua/ytdl_hook.lua. For example, an
| av://lavfi:ladspa=file= URL signifies that the product should call
| dlopen on a shared object file located at an arbitrary local pathname.
| The issue exists because the product does not consider that youtube-dl
| can provide a potentially unsafe URL.
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2018-6360
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-6360
[1] https://github.com/mpv-player/mpv/issues/5456
Regards,
Salvatore
--- End Message ---
--- Begin Message ---
Source: mpv
Source-Version: 0.23.0-2+deb9u2
We believe that the bug you reported is fixed in the latest version of
mpv, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to 889...@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
James Cowgill <jcowg...@debian.org> (supplier of updated mpv package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmas...@ftp-master.debian.org)
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256
Format: 1.8
Date: Thu, 08 Feb 2018 12:27:06 +0000
Source: mpv
Binary: mpv libmpv1 libmpv-dev mplayer2
Architecture: source amd64 all
Version: 0.23.0-2+deb9u2
Distribution: stretch-security
Urgency: high
Maintainer: Debian Multimedia Maintainers
<pkg-multimedia-maintain...@lists.alioth.debian.org>
Changed-By: James Cowgill <jcowg...@debian.org>
Description:
libmpv-dev - video player based on MPlayer/mplayer2 (client library dev files)
libmpv1 - video player based on MPlayer/mplayer2 (client library)
mplayer2 - transitional dummy package for mpv
mpv - video player based on MPlayer/mplayer2
Closes: 889892
Changes:
mpv (0.23.0-2+deb9u2) stretch-security; urgency=high
.
* debian/patches/08_ytdl-hook-whitelist-protocols.patch:
- Fix regression in CVE-2018-6360 patch which broke youtube playlists.
(Closes: #889892)
Checksums-Sha1:
483e70e1d85c2895c2c313dc0b6e2d393b08312b 2935 mpv_0.23.0-2+deb9u2.dsc
7198c199b83903b2f0882db831c429099f463c36 101984
mpv_0.23.0-2+deb9u2.debian.tar.xz
a34037a092be88db83fa046f4d64035c92ba238d 67938
libmpv-dev_0.23.0-2+deb9u2_amd64.deb
8090d05e7674bfbf67aa66c85bcc0f3103ad1483 2379788
libmpv1-dbgsym_0.23.0-2+deb9u2_amd64.deb
0103fb8c4f15762baa982e428fb6e40f45fc11ec 670790
libmpv1_0.23.0-2+deb9u2_amd64.deb
4a141b81accd3086bcb8dc7dc9776f6b10a16172 40636 mplayer2_0.23.0-2+deb9u2_all.deb
02950e329c4d94a7621b52d0e9013eb7086d8980 2396602
mpv-dbgsym_0.23.0-2+deb9u2_amd64.deb
48fb408c14ef98bd0692d69c676f4b2166e3e20e 17176
mpv_0.23.0-2+deb9u2_amd64.buildinfo
28487b4ecc25c687f2210d5c3be1657f5d157d95 875884 mpv_0.23.0-2+deb9u2_amd64.deb
Checksums-Sha256:
db8732bd7c711890682c431eaa80bc0f48e13e609c87add7e2e255595684c5b9 2935
mpv_0.23.0-2+deb9u2.dsc
e3458e1a8cad0edcd0488d6f3281940cde3ffa9d3e77ba13561a7121f12b8e5a 101984
mpv_0.23.0-2+deb9u2.debian.tar.xz
ec0a730e0769d5070f34e9421d13d4d448cffba17200407fc2107d8767deb015 67938
libmpv-dev_0.23.0-2+deb9u2_amd64.deb
6a5f0e9ab2fb86d2fd08fd10f88905968343327cf8321ba249798492f3f995f0 2379788
libmpv1-dbgsym_0.23.0-2+deb9u2_amd64.deb
e0a32ce4807d641b1ec4096ea710c885995d5cb27ea895897800a3ef7a42927e 670790
libmpv1_0.23.0-2+deb9u2_amd64.deb
ff5e5071f88dec2ffc566089e0ffab21f63fd34e489bf0803aba55646dbb4d7c 40636
mplayer2_0.23.0-2+deb9u2_all.deb
58312f0dcd864ee45c21362b607f3292a4236836d238ee321764b3a932ea88a9 2396602
mpv-dbgsym_0.23.0-2+deb9u2_amd64.deb
383d7a74e7a885f368c87e4874d14a2de1297fac1896c097fe0f0296e9e38308 17176
mpv_0.23.0-2+deb9u2_amd64.buildinfo
d992bb4a1cbaed416e3156a9a3dcf0a60aa7e1369d4bd6ae6146aa24f44fabcd 875884
mpv_0.23.0-2+deb9u2_amd64.deb
Files:
10d6842963e381adeb8b3547ff498e46 2935 video optional mpv_0.23.0-2+deb9u2.dsc
0e09c928a9567fb8f3f69d842ad26e24 101984 video optional
mpv_0.23.0-2+deb9u2.debian.tar.xz
14425412d59ef9a5e4b143e3f9117ea1 67938 libdevel optional
libmpv-dev_0.23.0-2+deb9u2_amd64.deb
1a586f92197da69ebf115f47cb30b9ad 2379788 debug extra
libmpv1-dbgsym_0.23.0-2+deb9u2_amd64.deb
e6bce029fae1bc57cf237a8b383968f5 670790 libs optional
libmpv1_0.23.0-2+deb9u2_amd64.deb
14f50f7b3325de2375a442020442e342 40636 oldlibs optional
mplayer2_0.23.0-2+deb9u2_all.deb
ea5060e776b57a7ba073584c49412a91 2396602 debug extra
mpv-dbgsym_0.23.0-2+deb9u2_amd64.deb
ee33a20ea1277b377f54181856d74c85 17176 video optional
mpv_0.23.0-2+deb9u2_amd64.buildinfo
3f9e619bd095bb477cbe0743acf16add 875884 video optional
mpv_0.23.0-2+deb9u2_amd64.deb
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCAAdFiEEayzFlnvRveqeWJspbsLe9o/+N3QFAlp84kEACgkQbsLe9o/+
N3SB3Q/+PKlOl24Rsfd0UWKUZevw/AdPFnc2wFKM4HmOYOdX5Gg73yWUQdrKYnr6
zYokeVcyzr5guxSQblzUY4V1AsSLfOjP81xEzBRtnTnx+fH4aqJd4H2C6zNcYdRp
FOl6i04qlBfSNlDy40cqwoIaZF9tyT8skDOu5j0yrh6k+VIdb+p4P3/7jJ6Ce25n
yv5RO83b/kirfZfUvx4SOwDuMIELatH2t7FP3zs6XecW58tpDHzVsISMJlHvR7FY
OB8Pt/VsBzTemh9NFFoGFFFGVdKvaH6Yq56GOdZgI0050KSgZodWzdmuCeF1DDdJ
Qfn4Prw5L876S7eKf9w343g278s0wjT0uanIQmaBH11m3e4bTPK8VstLR/tbILW2
Kpj3gLfR/23Dny7vOsk0MVMIFSCfuvB22txtjcBDH6xVV0zAwAPCJ77HcJpFdQVx
zxjjsknVljc6B2wNJ9gP3MNTr56FOjl7uFcJ++ZSFOpC9gOHVPZk+VVYy3lb7pDJ
D4Gv0Xn5xxySzI3fYhLDVc4pqyzG23HIsWCo0Ban7k7XUBy/B3lzPOaEJkizH4qS
tPy7VSED7eKappLKykDsoxEKXOVi3iNqhSgHjjZVpADCmEMGq1znKknqfjQNz1Wd
dlHvoKut325DVG7/fLgHrkvW/Lj06fIFuVXVbokKljFkK+5j6eg=
=cXSn
-----END PGP SIGNATURE-----
--- End Message ---