** Information type changed from Public to Public Security

** Summary changed:

- [SRU] Update to bugfix release 3.0.7 in Bionic
+ [SRU] Update to bugfix release 3.0.8 in Bionic

** Description changed:

  [Impact]
  
  VLC has received a bugfix update on the 3.0.x release path, which was
  recommended to us for additional stability in the Long Term Support
  release.
  
  [Test Case]
  
  Install vlc from bionic-proposed and test it for a decent amount of
  time. Play different video formats to catch any regressions, and use it
  as you normally would.
  
  [Regression Potential]
  
  The 3.0.x branch receives only bug fixes, which are cherry-picked from
  the master branch where the main development takes place. So, I think
  the regression potential is low.
  
  [Other Info]
  
  Here is the upstream Git repository:
  http://git.videolan.org/?p=vlc/vlc-3.0.git;a=summary
  
- We released the previous VLC bugfix release for this branch into Bionic
- in late July, see bug 1774067 for details. This was successful, and no
- regressions have been reported.
- 
  Upstream changelog:
  
- 
- Changes between 3.0.5 and 3.0.6:
- --------------------------------
+ Changes between 3.0.7.1 and 3.0.8:
+ ----------------------------------
  
  Core:
-  * Fix potential subtitle picture allocation failures
- 
- Codec:
-  * Add support for 12 bits decoding of AV1
-  * Fix HDR support in AV1 when the container provides the metadata
- 
- Changes between 3.0.4 and 3.0.5:
- --------------------------------
- 
- Access:
-  * Improve RTSP playback
-  * BluRay fixes and improvements, notably for menus and seeking
-  * Improve the UDP/RTP truncated issue
- 
- Codec:
-  * Add a new AV1 decoder based on dav1d library
-  * Enable libaom decoder by default
-  * Fix decoding of some HEVC streams with macOS hardware decoding
+  * Fix stuttering for low framerate videos
  
  Demux:
-  * MP4: Fix reading of some HDR metadata
-  * Miscellaneous AV1 demuxing improvements
-  * Fix CAF integer-underflow
-  * Fix an MKV crash on iOS 12.0, on iPhone XS phones
+  * Fix channel ordering in some MP4 files
+  * Fix glitches in TS over HLS
+  * Add real probing of HLS streams
+  * Fix HLS MIME type fallback
  
- Packetizer:
-  * Add an AV1 packetizer
+ Decoder:
+  * Fix WebVTT subtitles rendering
  
- macOS:
-  * Starting with VLC 3.0.5, VLC will be distributed with runtime hardening
-    enabled on macOS Mojave.
-    All external VLC plugins need to be signed by a DeveloperID certificate in 
order
-    to continue working with the official VLC package.
-  * Update the VLC dark UI to better match the dark mode of macOS Mojave
-  * Fix convert & save panel stream option
+ Stream filter:
+  * Improve network buffering
  
- Audio output:
-  * Fix corking when the playback state is paused
-  * Improve corking on Android
+ Misc:
+  * Update Youtube script
+ 
+ Audio Output:
+  * macOS/iOS: Fix stuttering or blank audio when starting or seeking when 
using external audio devices (bluetooth for example)
+  * macOS: Fix AV synchronization when using external audio devices
  
  Video Output:
-  * Fix Direct3D11 tone-mapping when HDR is displayed on an SDR screen
-  * More accurate colors for SD sources in Direct3D11
-  * Disable hardware decoding on some old Intel GPUs
-  * Fix zero-copy GPU acceleration on AMD RX Vega
-  * Misc Direct3D11 fixes
+  * Direct3D11: Fix hardware acceleration for some AMD drivers
  
- Miscellaneaous:
-  * Improve ChromeCast
-  * Update numerous 3rd party libraries, including for minor security issues
-  * Update Youtube support
-  * Fix subtitles rendering with specific fonts with negative horizontal 
advance
+ Stream output:
+  * Fix transcoding when the decoder does not set the chroma
+ 
+ Security:
+  * Fix a buffer overflow in the MKV demuxer (CVE-2019-14970)
+  * Fix a read buffer overflow in the avcodec decoder (CVE-2019-13962)
+  * Fix a read buffer overflow in the FAAD decoder
+  * Fix a read buffer overflow in the OGG demuxer (CVE-2019-14437, 
CVE-2019-14438)
+  * Fix a read buffer overflow in the ASF demuxer (CVE-2019-14776)
+  * Fix a use after free in the MKV demuxer (CVE-2019-14777, CVE-2019-14778)
+  * Fix a use after free in the ASF demuxer (CVE-2019-14533)
+  * Fix a couple of integer underflows in the MP4 demuxer (CVE-2019-13602)
+  * Fix a null dereference in the dvdnav demuxer
+  * Fix a null dereference in the ASF demuxer (CVE-2019-14534)
+  * Fix a null dereference in the AVI demuxer
+  * Fix a division by zero in the CAF demuxer (CVE-2019-14498)
+  * Fix a division by zero in the ASF demuxer (CVE-2019-14535)
+ 
+ Contribs:
+  * Update to a newer libmodplug version (0.8.9.0)

** Tags removed: cve-2018-19857
** Tags added: bionic

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1812480

Title:
  [SRU] Update to bugfix release 3.0.8 in Bionic

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/vlc/+bug/1812480/+subscriptions

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to