Uploaded 2733 now!
o Fixed an issue on systems without the ffmpeg development headers and libraries installed where some bits that depended on it were not conditional compiled.
1.24.0 Preview
- zoneminder
- Site Admin
- Posts: 5215
- Joined: Wed Jul 09, 2003 2:07 pm
- Location: Bristol, UK
- Contact:
- zoneminder
- Site Admin
- Posts: 5215
- Joined: Wed Jul 09, 2003 2:07 pm
- Location: Bristol, UK
- Contact:
Have the security issues mentioned in http://www.securityfocus.com/archive/1/ ... 0/threaded been fixed for this version? I'm a distribution maintainer(gentoo) and currently the package is masked from our users because it has these critical security issues. Are these fixed in the new version? If so, could we have a backported patch for 1.23?
Thanks,
Thomas
Thanks,
Thomas
- zoneminder
- Site Admin
- Posts: 5215
- Joined: Wed Jul 09, 2003 2:07 pm
- Location: Bristol, UK
- Contact:
Yes, they are fixed (AFAIK) in 1.24.0. I think I did a fix of all but the most trivial issues on 1.23.3 but I will have to check, it was certainly never released yet.tanderson wrote:Have the security issues mentioned in http://www.securityfocus.com/archive/1/ ... 0/threaded been fixed for this version? I'm a distribution maintainer(gentoo) and currently the package is masked from our users because it has these critical security issues. Are these fixed in the new version? If so, could we have a backported patch for 1.23?
Thanks,
Thomas
Phil
- zoneminder
- Site Admin
- Posts: 5215
- Joined: Wed Jul 09, 2003 2:07 pm
- Location: Bristol, UK
- Contact:
I came here looking for the same answer, so I hope you'll post the results of your review.zoneminder wrote:Yes, they are fixed (AFAIK) in 1.24.0. I think I did a fix of all but the most trivial issues on 1.23.3 but I will have to check, it was certainly never released yet.tanderson wrote:Have the security issues mentioned in http://www.securityfocus.com/archive/1/ ... 0/threaded been fixed for this version? I'm a distribution maintainer(gentoo) and currently the package is masked from our users because it has these critical security issues. Are these fixed in the new version? If so, could we have a backported patch for 1.23?
Thanks,
Thomas
-- Jack
- zoneminder
- Site Admin
- Posts: 5215
- Joined: Wed Jul 09, 2003 2:07 pm
- Location: Bristol, UK
- Contact:
I don't really have access to whatever test software that exposed the vulnerabilities was so I can't really say 100% they are fixed until the reporters retest. For 1.24.x I rewrote nearly all the web code to eliminate my understanding of the errors, for 1.23.3 I have done the most changes (ie injection etc) but stuff that requires access to the source web pages has not necessarily been addressed.
Phil
- zoneminder
- Site Admin
- Posts: 5215
- Joined: Wed Jul 09, 2003 2:07 pm
- Location: Bristol, UK
- Contact:
Updated to 2740.
o Should no longer moan about V4L2 cams that do not have a defined video standard
o Unconditionally or conditionally commented out V4L2 pix format defines that are not present in earlier kernels. There may be other ones from even earlier versions still to discover.
o Fixed issue with FireFox3 objecting to stream image resizing in mid stream.
o Should no longer moan about V4L2 cams that do not have a defined video standard
o Unconditionally or conditionally commented out V4L2 pix format defines that are not present in earlier kernels. There may be other ones from even earlier versions still to discover.
o Fixed issue with FireFox3 objecting to stream image resizing in mid stream.
Phil
- zoneminder
- Site Admin
- Posts: 5215
- Joined: Wed Jul 09, 2003 2:07 pm
- Location: Bristol, UK
- Contact: