crash in faad plugin

Bug #76566 reported by André Cruz
2
Affects Status Importance Assigned to Milestone
gstreamer0.10-ffmpeg (Ubuntu)
Invalid
Undecided
Unassigned
xine-lib (Ubuntu)
Fix Released
Medium
Unassigned

Bug Description

Binary package hint: libxine-extracodecs

Totem crashes when viewing this video in firefox:

http://www.bravia-advert.com/paint/thead/

Crash in the bundled faad plugin

Related branches

CVE References

Revision history for this message
André Cruz (andrefcruz) wrote :
Revision history for this message
Sebastien Bacher (seb128) wrote :

Thank you for your bug. The crash happens to libxine, reassigning

Sebastian Dröge (slomo)
Changed in gstreamer0.10-ffmpeg:
status: Unconfirmed → Rejected
Revision history for this message
Sebastien Bacher (seb128) wrote :
Download full text (17.4 KiB)

Debug backtrace for the crash:

309 time_out[nflat_ls+nshort+i] = overlap[nflat_ls+nshort+i] + transf_buf[nflat_ls+nshort+i];
#0 0xb16a41b5 in ifilter_bank (fb=0x880a608, window_sequence=1 '\001', window_shape=0 '\0', window_shape_prev=0 '\0',
    freq_in=0xb2b318fc, time_out=0x0, overlap=0x0, object_type=2 '\002', frame_len=1024) at filtbank.c:309
        i = <value optimized out>
        transf_buf = {-1.74421159e+13, -1.35806174e+13, -8.9573745e+12, -3.86334458e+12, 1.38111536e+12, 6.44637105e+12,
  1.10144877e+13, 1.47993731e+13, 1.75651695e+13, 1.9141369e+13, 1.94339574e+13, 1.84317368e+13, 1.62073506e+13,
  1.2913075e+13, 8.7714043e+12, 4.06120825e+12, -8.99935633e+11, -5.77586961e+12, -1.02334663e+13, -1.39641309e+13,
  -1.6704017e+13, -1.82515264e+13, -1.84811017e+13, -1.73522498e+13, -1.49133292e+13, -1.1299714e+13, -6.72641162e+12,
  -1.47560504e+12, 4.12031962e+12, 9.69900818e+12, 1.48906757e+13, 1.93413262e+13, 2.27354157e+13, 2.48163693e+13,
  2.54038235e+13, 2.44063341e+13, 2.18288022e+13, 1.77740993e+13, 1.24386133e+13, 6.10209523e+12, -8.87849878e+11,
  -8.13555096e+12, -1.52203229e+13, -2.17213567e+13, -2.72429482e+13, -3.14385671e+13, -3.40323142e+13, -3.48363979e+13,
  -3.3763539e+13, -3.08335828e+13, -2.61737551e+13, -2.00125972e+13, -1.26677743e+13, -4.52857535e+12, 3.96607593e+12,
  1.23525996e+13, 2.01694999e+13, 2.69840527e+13, 3.24175722e+13, 3.61675673e+13, 3.80255685e+13, 3.78895178e+13,
  3.57699179e+13, 3.17894542e+13, 2.61759571e+13, 1.92492507e+13, 1.14024985e+13, 3.07931723e+12, -5.25219188e+12,
  -1.31267318e+13, -2.01089991e+13, -2.58190134e+13, -2.99541358e+13, -3.2306463e+13, -3.27745368e+13, -3.1368711e+13,
  -2.82097625e+13, -2.35210235e+13, -1.76142313e+13, -1.08702959e+13, -3.71578451e+12, 3.40310229e+12, 1.00477971e+13,
  1.58140046e+13, 2.03561883e+13, 2.34084693e+13, 2.48005442e+13, 2.44677912e+13, 2.24548398e+13, 1.891249e+13,
  1.40880286e+13, 8.30973254e+12, 1.96625092e+12, -4.51761668e+12, -1.07075202e+13, -1.61867146e+13, -2.05822215e+13,
  -2.35883777e+13, -2.49862637e+13, -2.46579483e+13, -2.25944367e+13, -1.88971053e+13, -1.37722195e+13, -7.51906849e+12,
  -5.12253133e+11, 6.82068961e+12, 1.40251192e+13, 2.06468976e+13, 2.62602186e+13, 3.04938568e+13, 3.30543745e+13,
  3.37447381e+13, 3.24772802e+13, 2.92801741e+13, 2.42969613e+13, 1.77792184e+13, 1.00726315e+13, 1.59744668e+12,
  -7.17573692e+12, -1.57532176e+13, -2.36470812e+13, -3.04037841e+13, -3.56309396e+13, -3.90205874e+13, -4.03675252e+13,
  -3.95817853e+13, -3.66942167e+13, -3.18551496e+13, -2.53259017e+13, -1.74639095e+13, -8.70205725e+12, 4.76216459e+11,
  9.56497605e+12, 1.80649617e+13, 2.55124434e+13, 3.1505871e+13, 3.57288641e+13, 3.79680897e+13, 3.81250615e+13,
  3.62211663e+13, 3.23955605e+13, 2.68962449e+13, 2.00646423e+13, 1.23148918e+13, 4.10885476e+12, -4.07147328e+12,
  -1.17525803e+13, -1.84973923e+13, -2.39307776e+13, -2.77612656e+13, -2.97975268e+13, -2.99587915e+13, -2.82784988e+13,
  -2.49011047e+13, -2.00721522e+13, -1.41224061e+13, -7.44682213e+12, -4.79893029e+11, 6.33132601e+12, 1.25547535e+13,
  1.77996971e+13, 2.17406421e+13, 2.41368522e+13, 2.48467465e+13, 2.38360472e+1...

description: updated
Changed in xine-lib:
importance: Undecided → Medium
status: Unconfirmed → Confirmed
Revision history for this message
Reinhard Tartler (siretart) wrote :

the referenced link is dead. could you please attach an example file to this bug?

Changed in xine-lib:
status: Confirmed → Incomplete
Revision history for this message
Connor Imes (ckimes) wrote :

Thank you for taking the time to report this bug and helping to make Ubuntu better. You reported this bug a while ago and there hasn't been any activity in it recently. We were wondering is this still an issue for you? Can you try with latest Ubuntu release? Thanks in advance.

Revision history for this message
Launchpad Janitor (janitor) wrote :

This bug was fixed in the package xine-lib - 1.1.15-0ubuntu1

---------------
xine-lib (1.1.15-0ubuntu1) intrepid; urgency=low

  * New upstream release (LP: #261135)
    - introduces updated faad plugin (LP: #76566, #123456)
    - Fixes CVE-2008-3231

 -- Reinhard Tartler <email address hidden> Tue, 26 Aug 2008 21:07:40 +0200

Changed in xine-lib:
status: Incomplete → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Bug attachments

Remote bug watches

Bug watches keep track of this bug in other bug trackers.