[Git][security-tracker-team/security-tracker][master] 2 commits: [libav LTS triaging] data/CVE/list: Add ffmpeg upstream commit that fixes…
Mike Gabriel
sunweaver at debian.org
Fri Nov 30 20:13:29 GMT 2018
Mike Gabriel pushed to branch master at Debian Security Tracker / security-tracker
Commits:
31840bfd by Mike Gabriel at 2018-11-30T20:13:14Z
[libav LTS triaging] data/CVE/list: Add ffmpeg upstream commit that fixes CVE-2015-6825 for libav in jessie.
- - - - -
d2462ccd by Mike Gabriel at 2018-11-30T20:13:14Z
data/dla-needed.txt: in libav notes, replace some "," by ":".
- - - - -
2 changed files:
- data/CVE/list
- data/dla-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -143976,8 +143976,9 @@ CVE-2015-6826 (The ff_rv34_decode_init_thread_copy function in libavcodec/rv34.c
CVE-2015-6825 (The ff_frame_thread_init function in libavcodec/pthread_frame.c in ...)
- ffmpeg 7:2.7.2-1
[squeeze] - ffmpeg <end-of-life> (Not supported in Squeeze LTS)
- - libav <undetermined>
+ - libav <removed>
[wheezy] - libav <not-affected> (Vulnerable code not present)
+ NOTE: http://git.videolan.org/?p=ffmpeg.git;a=commitdiff;h=f1a38264f20382731cf2cc75fdd98f4c9a84a626
CVE-2015-6824 (The sws_init_context function in libswscale/utils.c in FFmpeg before ...)
- ffmpeg 7:2.7.2-1
[squeeze] - ffmpeg <end-of-life> (Not supported in Squeeze LTS)
=====================================
data/dla-needed.txt
=====================================
@@ -31,8 +31,9 @@ libav (Markus Koschany, Mike Gabriel)
NOTE: 20181130: CVE-2015-6820: patch available, issue untested (no PoC), vulnerable
NOTE: 20181130: CVE-2015-6821: patch available, issue untested (no PoC), vulnerable
NOTE: 20181130: CVE-2015-6822: patch available, issue untested (no PoC), vulnerable
- NOTE: 20181130: CVE-2015-6823, patch available, issue untested (no PoC), vulnerable
- NOTE: 20181130: CVE-2015-6824, patch available, issue untested (no PoC), vulnerable
+ NOTE: 20181130: CVE-2015-6823: patch available, issue untested (no PoC), vulnerable
+ NOTE: 20181130: CVE-2015-6824: patch available, issue untested (no PoC), vulnerable
+ NOTE: 20181130: CVE-2015-6825: patch available, issue untested (no PoC), vulnerable
--
libsndfile (Hugo Lefeuvre)
NOTE: 20181123: CVE-2018-19432 minor but several older CVEs triaged no-dsa (such as CVE-2017-8361)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/compare/7c536a399a9d7e956e6ebb375279ee201ca93675...d2462ccd55c1e37154108dd777b90b96e2f1bdb4
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/compare/7c536a399a9d7e956e6ebb375279ee201ca93675...d2462ccd55c1e37154108dd777b90b96e2f1bdb4
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20181130/31639e67/attachment-0001.html>
More information about the debian-security-tracker-commits
mailing list