[Secure-testing-commits] r24639 - data/CVE

Moritz Muehlenhoff jmm at moszumanska.debian.org
Mon Dec 9 09:22:54 UTC 2013


Author: jmm
Date: 2013-12-09 09:22:54 +0000 (Mon, 09 Dec 2013)
New Revision: 24639

Modified:
   data/CVE/list
Log:
ffmpeg triage


Modified: data/CVE/list
===================================================================
--- data/CVE/list	2013-12-09 07:08:24 UTC (rev 24638)
+++ data/CVE/list	2013-12-09 09:22:54 UTC (rev 24639)
@@ -85,104 +85,96 @@
 CVE-2014-0326
 	RESERVED
 CVE-2013-7024
-	- ffmpeg <removed>
-	- libav <unfixed>
+	- ffmpeg <not-affected> (Vulnerable code not present)
+	- libav <not-affected> (Vulnerable code not present)
 	NOTE: https://github.com/FFmpeg/FFmpeg/commit/fe448cd28d674c3eff3072552eae366d0b659ce9
 	NOTE: https://trac.ffmpeg.org/ticket/2921
-	TODO: check
+	NOTE: Only present in libav trunk
 CVE-2013-7023
 	- ffmpeg <removed>
 	- libav <unfixed>
 	NOTE: https://github.com/FFmpeg/FFmpeg/commit/f31011e9abfb2ae75bb32bc44e2c34194c8dc40a
 	NOTE: https://trac.ffmpeg.org/ticket/2982
-	TODO: check
 CVE-2013-7022
-	- ffmpeg <removed>
-	- libav <unfixed>
+	- ffmpeg <not-affected> (Vulnerable code not present)
+	- libav <not-affected> (Vulnerable code not present)
 	NOTE: https://github.com/FFmpeg/FFmpeg/commit/e07ac727c1cc9eed39e7f9117c97006f719864bd
 	NOTE: https://trac.ffmpeg.org/ticket/2971
-	TODO: check
+	NOTE: Only present in libav trunk
 CVE-2013-7021
-	- ffmpeg <removed>
+	- ffmpeg <not-affected> (Vulnerable code not present)
 	- libav <unfixed>
+	[wheezy] - libav <not-affected> (Vulnerable code not present)
 	NOTE: https://github.com/FFmpeg/FFmpeg/commit/cdd5df8189ff1537f7abe8defe971f80602cc2d2
 	NOTE: https://trac.ffmpeg.org/ticket/2905
-	TODO: check
 CVE-2013-7020
 	- ffmpeg <removed>
 	- libav <unfixed>
 	NOTE: https://github.com/FFmpeg/FFmpeg/commit/b05cd1ea7e45a836f7f6071a716c38bb30326e0f
-	TODO: check
 CVE-2013-7019
-	- ffmpeg <removed>
-	- libav <unfixed>
+	- ffmpeg <not-affected> (Vulnerable code not present)
+	- libav <not-affected> (Vulnerable code not present)
 	NOTE: https://github.com/FFmpeg/FFmpeg/commit/a1b9004b768bef606ee98d417bceb9392ceb788d
 	NOTE: https://trac.ffmpeg.org/ticket/2898
-	TODO: check
+	NOTE: Only present in libav trunk
 CVE-2013-7018
-	- ffmpeg <removed>
-	- libav <unfixed>
+	- ffmpeg <not-affected> (Vulnerable code not present)
+	- libav <not-affected> (Vulnerable code not present)
 	NOTE: https://github.com/FFmpeg/FFmpeg/commit/9a271a9368eaabf99e6c2046103acb33957e63b7
 	NOTE: https://trac.ffmpeg.org/ticket/2895
-	TODO: check
+	NOTE: Only present in libav trunk
 CVE-2013-7017
-	- ffmpeg <removed>
-	- libav <unfixed>
+	- ffmpeg <not-affected> (Vulnerable code not present)
+	- libav <not-affected> (Vulnerable code not present)
 	NOTE: https://github.com/FFmpeg/FFmpeg/commit/912ce9dd2080c5837285a471d750fa311e09b555
-	TODO: check
+	NOTE: Only present in libav trunk
 CVE-2013-7016
-	- ffmpeg <removed>
-	- libav <unfixed>
+	- ffmpeg <not-affected> (Vulnerable code not present)
+	- libav <not-affected> (Vulnerable code not present)
 	NOTE: https://github.com/FFmpeg/FFmpeg/commit/8bb11c3ca77b52e05a9ed1496a65f8a76e6e2d8f
 	NOTE: https://trac.ffmpeg.org/ticket/2848
-	TODO: check
+	NOTE: Only present in libav trunk
 CVE-2013-7015
 	- ffmpeg <removed>
 	- libav <unfixed>
 	NOTE: https://github.com/FFmpeg/FFmpeg/commit/880c73cd76109697447fbfbaa8e5ee5683309446
 	NOTE: https://trac.ffmpeg.org/ticket/2844
-	TODO: check
 CVE-2013-7014
-	- ffmpeg <removed>
+	- ffmpeg <not-affected> (Vulnerable code not present)
 	- libav <unfixed>
 	NOTE: https://github.com/FFmpeg/FFmpeg/commit/86736f59d6a527d8bc807d09b93f971c0fe0bb07
 	NOTE: https://trac.ffmpeg.org/ticket/2919
-	TODO: check
 CVE-2013-7013
-	- ffmpeg <removed>
-	- libav <unfixed>
+	- ffmpeg <not-affected> (Vulnerable code not present)
+	- libav <not-affected> (Vulnerable code not present)
 	NOTE: https://github.com/FFmpeg/FFmpeg/commit/821a5938d100458f4d09d634041b05c860554ce0
 	NOTE: https://trac.ffmpeg.org/ticket/2922
-	TODO: check
+	NOTE: Only present in libav trunk
 CVE-2013-7012
-	- ffmpeg <removed>
-	- libav <unfixed>
+	- ffmpeg <not-affected> (Vulnerable code not present)
+	- libav <not-affected> (Vulnerable code not present)
 	NOTE: https://github.com/FFmpeg/FFmpeg/commit/780669ef7c23c00836a24921fcc6b03be2b8ca4a
 	NOTE: https://trac.ffmpeg.org/ticket/3080
-	TODO: check
+	NOTE: Only present in libav trunk
 CVE-2013-7011
 	- ffmpeg <removed>
 	- libav <unfixed>
 	NOTE: https://github.com/FFmpeg/FFmpeg/commit/547d690d676064069d44703a1917e0dab7e33445
 	NOTE: https://trac.ffmpeg.org/ticket/2906
-	TODO: check
 CVE-2013-7010
 	- ffmpeg <removed>
 	- libav <unfixed>
 	NOTE: https://github.com/FFmpeg/FFmpeg/commit/454a11a1c9c686c78aa97954306fb63453299760
-	TODO: check
 CVE-2013-7009
 	- ffmpeg <removed>
 	- libav <unfixed>
 	NOTE: https://github.com/FFmpeg/FFmpeg/commit/3819db745da2ac7fb3faacb116788c32f4753f34
 	NOTE: https://trac.ffmpeg.org/ticket/2850
-	TODO: check
 CVE-2013-7008
-	- ffmpeg <removed>
+	- ffmpeg <not-affected> (Vulnerable code not present)
 	- libav <unfixed>
 	NOTE: https://github.com/FFmpeg/FFmpeg/commit/29ffeef5e73b8f41ff3a3f2242d356759c66f91f
 	NOTE: https://trac.ffmpeg.org/ticket/2927
-	TODO: check
 CVE-2013-7001 (The Multimedia Messaging Centre (MMSC) in NowSMS Now SMS & MMS Gateway ...)
 	NOT-FOR-US: NowSMS
 CVE-2013-7000 (The Multimedia Messaging Centre (MMSC) in NowSMS Now SMS & MMS Gateway ...)




More information about the Secure-testing-commits mailing list