<feed xmlns='http://www.w3.org/2005/Atom'>
<title>linux/poky.git/meta/recipes-multimedia, branch yocto-3.1.12</title>
<subtitle>Mirror of git.yoctoproject.org/poky</subtitle>
<id>https://git.enea.com/cgit/linux/poky.git/atom?h=yocto-3.1.12</id>
<link rel='self' href='https://git.enea.com/cgit/linux/poky.git/atom?h=yocto-3.1.12'/>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/poky.git/'/>
<updated>2021-11-11T10:54:32+00:00</updated>
<entry>
<title>meta: Add explict branch to git SRC_URIs, handle github url changes</title>
<updated>2021-11-11T10:54:32+00:00</updated>
<author>
<name>Steve Sakoman</name>
<email>steve@sakoman.com</email>
</author>
<published>2021-11-02T14:45:10+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/poky.git/commit/?id=07be05c69896b6d9f4da4b3ba122a1668c8c1200'/>
<id>urn:sha1:07be05c69896b6d9f4da4b3ba122a1668c8c1200</id>
<content type='text'>
This update was made with the convert-scruri.py script in scripts/contrib

This script handles two emerging issues:

    1. There is uncertainty about the default branch name in git going forward.
    To try and cover the different possible outcomes, add branch names to all
    git:// and gitsm:// SRC_URI entries.

    2. Github are dropping support for git:// protocol fetching, so remap github
     urls as needed. For more details see:

    https://github.blog/2021-09-01-improving-git-protocol-security-github/

(From OE-Core rev: 827a805349f9732b2a5fa9184dc7922af36de327)

Signed-off-by: Steve Sakoman &lt;steve@sakoman.com&gt;
Signed-off-by: Richard Purdie &lt;richard.purdie@linuxfoundation.org&gt;
</content>
</entry>
<entry>
<title>ffmpeg: Add fix for CVEs</title>
<updated>2021-10-23T22:14:16+00:00</updated>
<author>
<name>Saloni</name>
<email>salonij@kpit.com</email>
</author>
<published>2021-10-05T15:02:21+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/poky.git/commit/?id=e86adf76ab5622add5d7632006104fe448094ff5'/>
<id>urn:sha1:e86adf76ab5622add5d7632006104fe448094ff5</id>
<content type='text'>
Add fix for below CVE:
CVE-2021-3566
Link: [http://git.videolan.org/?p=ffmpeg.git;a=patch;h=3bce9e9b3ea35c54bacccc793d7da99ea5157532]

CVE-2021-38291
Link: [http://git.videolan.org/?p=ffmpeg.git;a=patch;h=e01d306c647b5827102260b885faa223b646d2d1]

(From OE-Core rev: 89df45b9e69a0d5c62a7e05156bc0d3fc85c77fd)

Signed-off-by: Saloni Jain &lt;jainsaloni0918@gmail.com&gt;
Signed-off-by: Steve Sakoman &lt;steve@sakoman.com&gt;
Signed-off-by: Richard Purdie &lt;richard.purdie@linuxfoundation.org&gt;
</content>
</entry>
<entry>
<title>libsamplerate0: Set correct soname for 0.1.9</title>
<updated>2021-10-07T14:10:33+00:00</updated>
<author>
<name>Tom Pollard</name>
<email>tom.pollard@codethink.co.uk</email>
</author>
<published>2021-09-24T12:47:57+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/poky.git/commit/?id=1d175bfd8526f20e0a440f59a2515736a0c17e26'/>
<id>urn:sha1:1d175bfd8526f20e0a440f59a2515736a0c17e26</id>
<content type='text'>
Manually patch SHARED_VERSION_INFO, which was missed in
the 0.1.9 release and later incorrectly fixed until 0.2.1

(From OE-Core rev: eb637a677dfed8680d680349e616a358795a7d56)

Signed-off-by: Tom Pollard &lt;tom.pollard@codethink.co.uk&gt;
Signed-off-by: Richard Purdie &lt;richard.purdie@linuxfoundation.org&gt;
(cherry picked from commit cb2e8efd316d44b9b1453882114856e0eb7b3500)
Signed-off-by: Steve Sakoman &lt;steve@sakoman.com&gt;
Signed-off-by: Richard Purdie &lt;richard.purdie@linuxfoundation.org&gt;
</content>
</entry>
<entry>
<title>libsndfile: Security fix for CVE-2021-3246</title>
<updated>2021-09-29T23:02:22+00:00</updated>
<author>
<name>Armin Kuster</name>
<email>akuster@mvista.com</email>
</author>
<published>2021-09-15T00:04:57+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/poky.git/commit/?id=874fe76b00f7a8b31477417611df9929c21c1eaf'/>
<id>urn:sha1:874fe76b00f7a8b31477417611df9929c21c1eaf</id>
<content type='text'>
Source: https://github.com/libsndfile/libsndfile
MR: 112098
Type: Security Fix
Disposition: Backport from https://github.com/libsndfile/libsndfile/pull/713
ChangeID: 10d137de063b7a1e543ee96fbcf948945a452869
Description:

(From OE-Core rev: f999bac187a935821f8580f3c5b1d08107ba9851)

Signed-off-by: Armin Kuster &lt;akuster@mvista.com&gt;
Signed-off-by: Steve Sakoman &lt;steve@sakoman.com&gt;
Signed-off-by: Richard Purdie &lt;richard.purdie@linuxfoundation.org&gt;
</content>
</entry>
<entry>
<title>gstreamer: ignore CVE-2021-3497, CVE-2021-3498, and CVE-2021-3522</title>
<updated>2021-08-10T10:14:10+00:00</updated>
<author>
<name>Steve Sakoman</name>
<email>steve@sakoman.com</email>
</author>
<published>2021-07-26T14:22:32+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/poky.git/commit/?id=4542e5f944051c56235930a8a457a473026fa219'/>
<id>urn:sha1:4542e5f944051c56235930a8a457a473026fa219</id>
<content type='text'>
CPE entries for gst-plugins-* are listed as gstreamer issues
so we need to ignore the false hits for the CVEs we've patched
in plugins recipes

(From OE-Core rev: 55140153e66f13a2d8a673a48f6c21e293415e56)

Signed-off-by: Steve Sakoman &lt;steve@sakoman.com&gt;
Signed-off-by: Richard Purdie &lt;richard.purdie@linuxfoundation.org&gt;
</content>
</entry>
<entry>
<title>Revert "gstreamer-plugins-base: ignore CVE-2021-3522 since it is fixed"</title>
<updated>2021-08-10T10:14:10+00:00</updated>
<author>
<name>Steve Sakoman</name>
<email>steve@sakoman.com</email>
</author>
<published>2021-07-26T14:20:58+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/poky.git/commit/?id=427882f470377e05a5fda52c1aa968398579a12f'/>
<id>urn:sha1:427882f470377e05a5fda52c1aa968398579a12f</id>
<content type='text'>
Change is correct but should be in gstreamer recipe not gstreamer-plugins-base

This reverts commit f32e90a7f8918aacda61ef6176eb1655742045b4.

Signed-off-by: Richard Purdie &lt;richard.purdie@linuxfoundation.org&gt;
</content>
</entry>
<entry>
<title>Revert "gstreamer-plugins-good: ignore CVE-2021-3497/8 since they are fixed"</title>
<updated>2021-08-10T10:14:10+00:00</updated>
<author>
<name>Steve Sakoman</name>
<email>steve@sakoman.com</email>
</author>
<published>2021-07-26T14:17:52+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/poky.git/commit/?id=8cdd3eb6e6b0daeef7c87ad4ecbfb91459e125d2'/>
<id>urn:sha1:8cdd3eb6e6b0daeef7c87ad4ecbfb91459e125d2</id>
<content type='text'>
Change is correct but should be in gstreamer recipe not gstreamer-plugins-good

This reverts commit d853e2bde1ea083f8438e8d7a80f041196d2e38d.

Signed-off-by: Richard Purdie &lt;richard.purdie@linuxfoundation.org&gt;
</content>
</entry>
<entry>
<title>gstreamer-plugins-good: ignore CVE-2021-3497/8 since they are fixed</title>
<updated>2021-07-20T18:05:39+00:00</updated>
<author>
<name>Steve Sakoman</name>
<email>steve@sakoman.com</email>
</author>
<published>2021-07-14T22:14:20+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/poky.git/commit/?id=3b49f3536e4bd4454a03ae95ef9a199fa06f878f'/>
<id>urn:sha1:3b49f3536e4bd4454a03ae95ef9a199fa06f878f</id>
<content type='text'>
CPE entries for gst-plugins-good are listed as gstreamer issues
so we need to ignore the false hits for the two CVEs we've patched

(From OE-Core rev: d853e2bde1ea083f8438e8d7a80f041196d2e38d)

Signed-off-by: Steve Sakoman &lt;steve@sakoman.com&gt;
Signed-off-by: Richard Purdie &lt;richard.purdie@linuxfoundation.org&gt;
</content>
</entry>
<entry>
<title>gstreamer-plugins-base: ignore CVE-2021-3522 since it is fixed</title>
<updated>2021-07-20T18:05:39+00:00</updated>
<author>
<name>Steve Sakoman</name>
<email>steve@sakoman.com</email>
</author>
<published>2021-07-14T22:09:06+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/poky.git/commit/?id=f2f6a73bb26a53632770b1de4bbbb4e130539524'/>
<id>urn:sha1:f2f6a73bb26a53632770b1de4bbbb4e130539524</id>
<content type='text'>
CPE entries for gst-plugins-base are listed as gstreamer issues
so we need to ignore the false hit for the CVE we've patched

(From OE-Core rev: f32e90a7f8918aacda61ef6176eb1655742045b4)

Signed-off-by: Steve Sakoman &lt;steve@sakoman.com&gt;
Signed-off-by: Richard Purdie &lt;richard.purdie@linuxfoundation.org&gt;
</content>
</entry>
<entry>
<title>gstreamer-plugins-base: fix CVE-2021-3522</title>
<updated>2021-07-10T21:46:19+00:00</updated>
<author>
<name>Minjae Kim</name>
<email>flowergom@gmail.com</email>
</author>
<published>2021-07-05T09:41:13+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/poky.git/commit/?id=44f67a81563f77c82be48f102b3fa38303fb80ef'/>
<id>urn:sha1:44f67a81563f77c82be48f102b3fa38303fb80ef</id>
<content type='text'>
Out-of-bounds read in ID3v2 tag parsing

reference:
https://gstreamer.freedesktop.org/security/sa-2021-0001.html
(From OE-Core rev: 8cab9d3dd226e854d40e12df497456adc3d3f81d)

Signed-off-by: Steve Sakoman &lt;steve@sakoman.com&gt;
Signed-off-by: Richard Purdie &lt;richard.purdie@linuxfoundation.org&gt;
</content>
</entry>
</feed>
