release notes and changelog for 0.6.2

Reinhard Tartler committed Mar 18, 2011
Entries are sorted chronologically from oldest to youngest within each release,
releases are sorted from youngest to oldest.
+version 0.6.2:
+- Fix invalid reads in VC-1 decoding (related to CVE-2011-0723)
+- Do not attempt to decode APE file with no frames
+ (adresses
version 0.6.1:
- fix autodetection of E-AC-3 substream samples
This release includes a backport of the AAC decoder from trunk, which
enables proper playback of HE-AAC v2 media.
+* 0.6.2
+General notes
+This is a maintenance-only release that addresses a small number of security
+and portability issues. Distributors and system integrators are encouraged
+to update and share their patches against this branch.
+Security fixes
+Programming errors in container and codec implementations may lead to
+denial of service or the execution of arbitrary code if the user is
+tricked into opening a malformed media file or stream.
+Affected and updated have been the implementations of the following
+codecs and container formats:
+ - VC1 decoder (Change related to CVE-2011-0723)
+ - APE decoder (cf.

