[Git][security-tracker-team/security-tracker][master] [libav LTS triaging] data/dla-needed.txt. Add note about false upstream commit…
Mike Gabriel
sunweaver at debian.org
Thu Dec 20 15:34:40 GMT 2018
Mike Gabriel pushed to branch master at Debian Security Tracker / security-tracker
Commits:
2dd16ccd by Mike Gabriel at 2018-12-20T15:33:46Z
[libav LTS triaging] data/dla-needed.txt. Add note about false upstream commit URLs. data/CVE/list: Update upstream commit URLs for CVE-2015-6823 and CVE-2015-6824
- - - - -
2 changed files:
- data/CVE/list
- data/dla-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -149327,13 +149327,13 @@ CVE-2015-6824 (The sws_init_context function in libswscale/utils.c in FFmpeg bef
- ffmpeg 7:2.7.2-1
[squeeze] - ffmpeg <end-of-life> (Not supported in Squeeze LTS)
- libav <removed>
- NOTE: http://git.videolan.org/?p=ffmpeg.git;a=commitdiff;h=39bbdebb1ed8eb9c9b0cd6db85afde6ba89d86e4
+ NOTE: http://git.videolan.org/?p=ffmpeg.git;a=commitdiff;h=a5d44d5c220e12ca0cb7a4eceb0f74759cb13111
CVE-2015-6823 (The allocate_buffers function in libavcodec/alac.c in FFmpeg before ...)
{DLA-1611-1}
- ffmpeg 7:2.7.2-1
[squeeze] - ffmpeg <end-of-life> (Not supported in Squeeze LTS)
- libav <removed>
- NOTE: http://git.videolan.org/?p=ffmpeg.git;a=commitdiff;h=39bbdebb1ed8eb9c9b0cd6db85afde6ba89d86e4
+ NOTE: http://git.videolan.org/?p=ffmpeg.git;a=commitdiff;h=f7068bf277a37479aecde2832208d820682b35e6
CVE-2015-6822 (The destroy_buffers function in libavcodec/sanm.c in FFmpeg before ...)
{DLA-1611-1}
- ffmpeg 7:2.7.2-1
=====================================
data/dla-needed.txt
=====================================
@@ -61,6 +61,9 @@ libav (Markus Koschany, Mike Gabriel)
NOTE: 20181206: CVE-2016-9824: no patch available, PoC available (needs testing), currently <no-dsa>
NOTE: 20181206: CVE-2016-9825: no patch available, PoC available (needs testing), currently <ignored>
NOTE: 20181206: CVE-2016-9826: no patch available, PoC available (needs testing), currently <ignored>
+ NOTE: 20181220: Due to a flaw in security-tracker, CVE-2015-6823 and CVE-2015-6824 are not fixed in
+ NOTE: 20181220: +deb8u2 as mentioned in the changelog. The CVE/list file has now been updated with the
+ NOTE: 20181220: correct patches.
--
libphp-phpmailer
NOTE: 20181217: https://lists.debian.org/debian-lts/2018/12/msg00026.html
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/2dd16ccdc9f4cf132f7842b7f1427424e4732231
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/2dd16ccdc9f4cf132f7842b7f1427424e4732231
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20181220/3f094117/attachment-0001.html>
More information about the debian-security-tracker-commits
mailing list