Index: security/vuxml/vuln.xml =================================================================== --- security/vuxml/vuln.xml (revision 325042) +++ security/vuxml/vuln.xml (working copy) @@ -51,6 +51,73 @@ --> + + gstreamer-ffmpeg -- Multiple vulnerabilities in bundled libav + + + gstreamer-ffmpeg + 0.10.13_1 + + + + +
+

Bundled version of libav in gstreamer-ffmpeg contains a number of + vulnerabilities.

+
+ +
+ + CVE-2011-3892 + CVE-2011-3893 + CVE-2011-3895 + CVE-2011-3929 + CVE-2011-3936 + CVE-2011-3937 + CVE-2011-3940 + CVE-2011-3945 + CVE-2011-3947 + CVE-2011-3951 + CVE-2011-3952 + CVE-2011-4031 + CVE-2011-4351 + CVE-2011-4352 + CVE-2011-4353 + CVE-2011-4364 + CVE-2011-4579 + CVE-2012-0848 + CVE-2012-0850 + CVE-2012-0851 + CVE-2012-0852 + CVE-2012-0853 + CVE-2012-0858 + CVE-2012-0947 + CVE-2012-2772 + CVE-2012-2775 + CVE-2012-2777 + CVE-2012-2779 + CVE-2012-2783 + CVE-2012-2784 + CVE-2012-2786 + CVE-2012-2787 + CVE-2012-2788 + CVE-2012-2790 + CVE-2012-2791 + CVE-2012-2793 + CVE-2012-2794 + CVE-2012-2798 + CVE-2012-2800 + CVE-2012-2801 + CVE-2012-2803 + CVE-2012-5144 + http://libav.org/releases/libav-0.7.7.changelog + + + 2013-08-20 + 2013-08-20 + +
+ GnuPG and Libgcrypt -- side-channel attack vulnerability Index: multimedia/gstreamer-ffmpeg/Makefile =================================================================== --- multimedia/gstreamer-ffmpeg/Makefile (revision 325009) +++ multimedia/gstreamer-ffmpeg/Makefile (working copy) @@ -1,17 +1,16 @@ -# New ports collection makefile for: gstreamer ffmpeg -# Date created: Thu Feb 26 20:10:39 CET 2004 -# Whom: Koop Mast -# +# Created by: Koop Mast # $FreeBSD$ # $MCom: ports/multimedia/gstreamer-ffmpeg/Makefile,v 1.14 2006/07/20 13:40:27 ahze Exp $ -# PORTNAME= gstreamer PORTVERSION= 0.10.13 +PORTREVISION= 1 CATEGORIES= multimedia -MASTER_SITES= http://gstreamer.freedesktop.org/src/gst-ffmpeg/ +MASTER_SITES= http://gstreamer.freedesktop.org/src/gst-ffmpeg/:ffmpeg \ + http://libav.org/releases/:libav PKGNAMESUFFIX= -ffmpeg -DISTNAME= gst-ffmpeg-${PORTVERSION} +DISTFILES= gst-ffmpeg-${PORTVERSION}.tar.bz2:ffmpeg \ + libav-${LIBAV_VERSION}.tar.xz:libav MAINTAINER= multimedia@FreeBSD.org COMMENT= GStreamer plug-in for manipulating MPEG video streams @@ -19,10 +18,11 @@ LICENSE= GPLv2 BUILD_DEPENDS= yasm:${PORTSDIR}/devel/yasm -LIB_DEPENDS= orc-0.4.0:${PORTSDIR}/devel/orc +LIB_DEPENDS= liborc-0.4.so:${PORTSDIR}/devel/orc -USE_BZIP2= yes -USE_GMAKE= yes +LIBAV_VERSION= 0.7.7 +WRKSRC= ${WRKDIR}/gst-ffmpeg-${PORTVERSION} +USES= gmake pkgconfig USE_LDCONFIG= yes USE_GSTREAMER= yes GNU_CONFIGURE= yes @@ -67,4 +67,10 @@ .endif +post-patch: + @${MV} ${WRKSRC}/gst-libs/ext/libav ${WRKSRC}/gst-libs/ext/libav.old + @${MV} ${WRKDIR}/libav-${LIBAV_VERSION} ${WRKSRC}/gst-libs/ext/libav + @${CP} ${WRKSRC}/gst-libs/ext/libav.old/config.* \ + ${WRKSRC}/gst-libs/ext/libav/ + .include Index: multimedia/gstreamer-ffmpeg/distinfo =================================================================== --- multimedia/gstreamer-ffmpeg/distinfo (revision 325009) +++ multimedia/gstreamer-ffmpeg/distinfo (working copy) @@ -1,2 +1,4 @@ SHA256 (gst-ffmpeg-0.10.13.tar.bz2) = 76fca05b08e00134e3cb92fa347507f42cbd48ddb08ed3343a912def187fbb62 SIZE (gst-ffmpeg-0.10.13.tar.bz2) = 4784059 +SHA256 (libav-0.7.7.tar.xz) = 2d7b70c2bdaf8fea2e7d51838ce04e6c616cf90486134c247642fbdeafb21599 +SIZE (libav-0.7.7.tar.xz) = 3584936