{"id":"MGASA-2014-0071","summary":"Updated xbmc package fixes a security vulnerability","details":"Due to flaws in the embedded copy of libDCR, a fork of dcraw.c, in the\nembedded copy of CxImage, opening a specially crafted photo file could\ntrigger a division by zero, an infinite loop, or a null pointer\ndereference, resulting in a denial of service (CVE-2013-1438).\n\nThis update fixes those flaws.\n\nXBMC is also updated to a newer bugfix-only release, version 12.3.\nIt contains fixes to various issues, including:\n - several PVR related bugs\n - memory leaks\n - audio channel mapping\n - possible crash on progress dialog\nand more.\n\nAdditionally, this update fixes a compatibility issue on Mageia 4\naffecting AC-3 transcoding, which prevented, for example, multichannel\nplayback of AAC 5.1 files over S/PDIF or stereo-only HDMI devices.\n\nThe PVR addons have also been updated.\n","modified":"2026-04-16T06:22:56.310748820Z","published":"2014-02-16T12:54:48Z","upstream":["CVE-2013-1438"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2014-0071.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=12613"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=11149"},{"type":"WEB","url":"http://xbmc.org/xbmc-12-3-frodo-fixes/"}],"affected":[{"package":{"name":"xbmc","ecosystem":"Mageia:3","purl":"pkg:rpm/mageia/xbmc?arch=source&distro=mageia-3"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"12.3-1.1.mga3"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2014-0071.json"}},{"package":{"name":"xbmc","ecosystem":"Mageia:4","purl":"pkg:rpm/mageia/xbmc?arch=source&distro=mageia-4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"12.3-1.1.mga4"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2014-0071.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}