[Secure-testing-commits] r22829 - data/CVE

Moritz Muehlenhoff jmm at alioth.debian.org
Wed Jul 3 06:58:22 UTC 2013


Author: jmm
Date: 2013-07-03 06:58:21 +0000 (Wed, 03 Jul 2013)
New Revision: 22829

Modified:
   data/CVE/list
Log:
libav/ffmpeg updates
new kernel issue
filed bug for ansible


Modified: data/CVE/list
===================================================================
--- data/CVE/list	2013-07-03 00:52:04 UTC (rev 22828)
+++ data/CVE/list	2013-07-03 06:58:21 UTC (rev 22829)
@@ -2224,7 +2224,6 @@
 CVE-2013-3672 (The mm_decode_inter function in mmvideo.c in libavcodec in FFmpeg ...)
 	- ffmpeg <removed>
 	- libav <unfixed>
-	TODO: check
 	NOTE: http://git.videolan.org/?p=ffmpeg.git;a=commitdiff;h=8d3c99e825317b7efda5fd12e69896b47c700303
 CVE-2013-3671 (The format_line function in log.c in libavutil in FFmpeg before 1.2.1 ...)
 	- ffmpeg <not-affected> (Doesn't affect libav, specific to current ffmpeg)
@@ -5589,11 +5588,12 @@
 	RESERVED
 CVE-2013-2234
 	RESERVED
+	- linux-2.6 <removed>
+	- linux <unfixed>
 CVE-2013-2233 [not caching SSH host keys]
 	RESERVED
 	- ansible <unfixed>
 	NOTE: https://github.com/ansible/ansible/issues/857
-	TODO: check, report to BTS
 CVE-2013-2232
 	RESERVED
 CVE-2013-2231
@@ -9535,8 +9535,7 @@
 CVE-2013-0872 [libswresample/swresample.c out of array accesses]
 	RESERVED
 	- ffmpeg <not-affected> (libswresample not yet present in ffmpeg/0.5)
-	[wheezy] - libav <not-affected> (libavresample not yet present in libav/0.8)
-	- libav <unfixed>
+	- libav <not-affected> (libswresample not present in libav, linavresamle not affected)
 	NOTE: http://git.videolan.org/?p=ffmpeg.git;a=commitdiff;h=21cd905cd44a4bbafe8631bbaa6021d328413ce5
 CVE-2013-0871 (Race condition in the ptrace functionality in the Linux kernel before ...)
 	{DSA-2632-1}
@@ -9600,7 +9599,6 @@
 	RESERVED
 	- ffmpeg <removed>
 	- libav <unfixed>
-	NOTE: fixed in ffmpeg 1.0.4
 	NOTE: http://git.videolan.org/?p=ffmpeg.git;a=commitdiff;h=23318a57358358e7a4dc551e830e4503f0638cfe
 CVE-2013-0859 [libavcodec/tiff.c out of array access]
 	RESERVED




More information about the Secure-testing-commits mailing list