MPD Critical bug, please update to 0.12.2

Bug #94238 reported by Qball Cow
262
Affects Status Importance Assigned to Milestone
Dapper Backports
Fix Released
Medium
Unassigned
mpd (Ubuntu)
Fix Released
Undecided
William Grant
Declined for Dapper by Brandon Holtsclaw
Edgy
Fix Released
Undecided
William Grant
Feisty
Fix Released
Undecided
William Grant

Bug Description

Binary package hint: mpd

Just a note from the mpd dev-team.
We recently found a bug in mpd that allowed somebody to remotely crash mpd.
We just released a bugfix release (0.12.2) and advice to update this package asap.

Thx,

Qball

Revision history for this message
William Grant (wgrant) wrote :

Thanks for letting us know about this. Does it affect 0.11.5 too?

Revision history for this message
Qball Cow (qball-qballcow) wrote :

Not it doesn't.
I think it involves 0.12.0 and 0.12.1.

Revision history for this message
William Grant (wgrant) wrote :

Edgy and Feisty release versions are affected, as well as Dapper backports.

Revision history for this message
William Grant (wgrant) wrote :

I have an upload prepared for Feisty, and a pending UVFe at bug 94295. An Edgy debdiff is attached.

William Grant (wgrant)
Changed in mpd:
assignee: nobody → fujitsu
status: Unconfirmed → In Progress
assignee: nobody → fujitsu
status: Unconfirmed → In Progress
Revision history for this message
William Grant (wgrant) wrote :

0.12.2 uploaded to Feisty.

Changed in mpd:
status: In Progress → Fix Committed
William Grant (wgrant)
Changed in mpd:
status: Fix Committed → Fix Released
Revision history for this message
William Grant (wgrant) wrote :

Fixed in edgy-security.

Changed in mpd:
status: In Progress → Fix Released
Revision history for this message
Kees Cook (kees) wrote :

Published! Thanks. :)

Revision history for this message
John Dong (jdong) wrote :

Approved for backporting: mpd from *edgy-security* to dapper-backports

Changed in dapper-backports:
importance: Undecided → Medium
status: Unconfirmed → In Progress
Revision history for this message
Colin Watson (cjwatson) wrote :

 * Trying to backport mpd...
  - <mpd_0.12.1.orig.tar.gz: downloading from librarian>
  - <mpd_0.12.1-1ubuntu1.1.diff.gz: downloading from librarian>
  - <mpd_0.12.1-1ubuntu1.1.dsc: downloading from librarian>
I: Extracting mpd_0.12.1-1ubuntu1.1.dsc ... done.
I: Building backport of mpd-0.12.1 as 0.12.1-1ubuntu1.1~dapper1 ... done.

Changed in dapper-backports:
status: In Progress → Fix Released
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.