On 20/01/17 22:42, Jean-Marc Valin wrote:> This was reported as CVE-2017-0381 [1]. Contrary to that report, our own
> analysis [2] shows that no remote code execution is possible. However,
> we are making this release as a precaution. As usual, you can get it
> from the Opus website at: https://www.opus-codec.org/
The IPv6 servers are not updated:
"""
$ wget http://downloads.xiph.org/releases/opus/opus-1.1.4.tar.gz
--2017-01-20 22:52:15--
http://downloads.xiph.org/releases/opus/opus-1.1.4.tar.gz
Resolving downloads.xiph.org (downloads.xiph.org)...
2600:3404:200:237::2, 2605:bc80:3010::134, 2600:3402:200:227::2, ...
Connecting to downloads.xiph.org
(downloads.xiph.org)|2600:3404:200:237::2|:80... connected.
HTTP request sent, awaiting response... 404 Not Found
2017-01-20 22:52:16 ERROR 404: Not Found.
$ wget --inet4-only
http://downloads.xiph.org/releases/opus/opus-1.1.4.tar.gz
--2017-01-20 22:53:45--
http://downloads.xiph.org/releases/opus/opus-1.1.4.tar.gz
Resolving downloads.xiph.org (downloads.xiph.org)... 140.211.166.134
Connecting to downloads.xiph.org
(downloads.xiph.org)|140.211.166.134|:80... connected.
HTTP request sent, awaiting response... 200 OK
Length: 978830 (956K) [application/x-gzip]
Saving to: `opus-1.1.4.tar.gz'
100%[==========================================================================================>]
978,830 751K/s in 1.3s
2017-01-20 22:53:47 (751 KB/s) - `opus-1.1.4.tar.gz' saved [978830/978830]
"""
--
Jesús Cea Avión _/_/ _/_/_/ _/_/_/
jcea at jcea.es - http://www.jcea.es/ _/_/ _/_/ _/_/ _/_/ _/_/
Twitter: @jcea _/_/ _/_/ _/_/_/_/_/
jabber / xmpp:jcea at jabber.org _/_/ _/_/ _/_/ _/_/ _/_/
"Things are not so easy" _/_/ _/_/ _/_/ _/_/ _/_/ _/_/
"My name is Dump, Core Dump" _/_/_/ _/_/_/ _/_/ _/_/
"El amor es poner tu felicidad en la felicidad de otro" - Leibniz
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 473 bytes
Desc: OpenPGP digital signature
URL:
<http://lists.xiph.org/pipermail/opus/attachments/20170120/01b2b49c/attachment.sig>