Fedora Linux 8568 Published by

A libmediainfo security update has been released for Fedora 33.



SECURITY: Fedora 33 Update: libmediainfo-21.03-1.fc33


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2021-3b67623d93
2021-04-06 01:03:31.227619
--------------------------------------------------------------------------------

Name : libmediainfo
Product : Fedora 33
Version : 21.03
Release : 1.fc33
URL :   http://mediaarea.net/MediaInfo
Summary : Library for supplies technical and tag information about a video or audio file
Description :
This package contains the shared library for MediaInfo.
MediaInfo supplies technical and tag information about a video or
audio file.

What information can I get from MediaInfo?
* General: title, author, director, album, track number, date, duration...
* Video: codec, aspect, fps, bitrate...
* Audio: codec, sample rate, channels, language, bitrate...
* Text: language of subtitle
* Chapters: number of chapters, list of chapters

DivX, XviD, H263, H.263, H264, x264, ASP, AVC, iTunes, MPEG-1,
MPEG1, MPEG-2, MPEG2, MPEG-4, MPEG4, MP4, M4A, M4V, QuickTime,
RealVideo, RealAudio, RA, RM, MSMPEG4v1, MSMPEG4v2, MSMPEG4v3,
VOB, DVD, WMA, VMW, ASF, 3GP, 3GPP, 3GP2

What format (container) does MediaInfo support?
* Video: MKV, OGM, AVI, DivX, WMV, QuickTime, Real, MPEG-1,
MPEG-2, MPEG-4, DVD (VOB) (Codecs: DivX, XviD, MSMPEG4, ASP,
H.264, AVC...)
* Audio: OGG, MP3, WAV, RA, AC3, DTS, AAC, M4A, AU, AIFF
* Subtitles: SRT, SSA, ASS, SAMI

--------------------------------------------------------------------------------
Update Information:

Update mediainfo.
--------------------------------------------------------------------------------
ChangeLog:

* Sun Mar 28 2021 Vasiliy N. Glazov - 21.03-1
- Update to 21.03
* Tue Jan 26 2021 Fedora Release Engineering - 20.09-2
- Rebuilt for   https://fedoraproject.org/wiki/Fedora_34_Mass_Rebuild
--------------------------------------------------------------------------------
References:

[ 1 ] Bug #1940984 - CVE-2020-26797 mediainfo: heap-based buffer overflow via MediaInfoLib::File_Gxf::ChooseParser_ChannelGrouping [fedora-all]
  https://bugzilla.redhat.com/show_bug.cgi?id=1940984
[ 2 ] Bug #1940986 - CVE-2020-26797 libmediainfo: mediainfo: heap-based buffer overflow via MediaInfoLib::File_Gxf::ChooseParser_ChannelGrouping [fedora-all]
  https://bugzilla.redhat.com/show_bug.cgi?id=1940986
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2021-3b67623d93' at the command
line. For more information, refer to the dnf documentation available at
  http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
  https://fedoraproject.org/keys