[Secure-testing-commits] [Git][security-tracker-team/security-tracker][master] Add fixed version for CVE-2015-1208/ffmpeg

Salvatore Bonaccorso carnil at debian.org
Sat Jan 13 10:24:07 UTC 2018


Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
8393e262 by Salvatore Bonaccorso at 2018-01-13T11:21:12+01:00
Add fixed version for CVE-2015-1208/ffmpeg

The first version uploaded to unstable, 7:2.5-1, after the 2.4.x series
did not contain the fix, neither 2.5.1 upstream, only then later in
2.5.3.

I have not verfied that in later series, the fix got not lost again and
possibly then reintroduced via a bugfix release.

Thus please double-check this CVE entry.

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
--- a/data/CVE/list
+++ b/data/CVE/list
@@ -117636,7 +117636,8 @@ CVE-2015-1209 (Use-after-free vulnerability in the ...)
 	[wheezy] - chromium-browser <end-of-life>
 	[squeeze] - chromium-browser <end-of-life>
 CVE-2015-1208 (Integer underflow in the mov_read_default function in ...)
-	TODO: check
+	- ffmpeg 7:2.5.3-1
+	NOTE: http://git.videolan.org/?p=ffmpeg.git;a=commit;h=3ebd76a9c57558e284e94da367dd23b435e6a6d0
 CVE-2015-1207 (Double-free vulnerability in libavformat/mov.c in FFMPEG in Google ...)
 	- ffmpeg 7:2.6.1-1
 	- libav <removed>



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/8393e262faf0b1dcca129c6039a6489447a83774

---
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/8393e262faf0b1dcca129c6039a6489447a83774
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.alioth.debian.org/pipermail/secure-testing-commits/attachments/20180113/3997ca74/attachment-0001.html>


More information about the Secure-testing-commits mailing list