[Secure-testing-commits] r44906 - data/CVE

Salvatore Bonaccorso carnil at moszumanska.debian.org
Mon Sep 26 05:57:45 UTC 2016


Author: carnil
Date: 2016-09-26 05:57:45 +0000 (Mon, 26 Sep 2016)
New Revision: 44906

Modified:
   data/CVE/list
Log:
Add CVE-2016-7554/ffmpeg

Modified: data/CVE/list
===================================================================
--- data/CVE/list	2016-09-26 05:46:48 UTC (rev 44905)
+++ data/CVE/list	2016-09-26 05:57:45 UTC (rev 44906)
@@ -2150,8 +2150,11 @@
 	RESERVED
 CVE-2016-7555
 	RESERVED
-CVE-2016-7554
+CVE-2016-7554 [overread end of atom 'stsd' by 4294967134 bytes]
 	RESERVED
+	- ffmpeg <unfixed>
+	NOTE: Reproducer as in afl source ffmpeg-h264-call-stack-overflow.mp4
+	NOTE: http://www.openwall.com/lists/oss-security/2016/09/25/2
 CVE-2016-7552
 	RESERVED
 CVE-2016-7549




More information about the Secure-testing-commits mailing list