[Git][security-tracker-team/security-tracker][master] [libav LTS triaging] data/CVE/list: Tag CVE-2015-8217 for libav in jessie with <not-affected>.

Mike Gabriel sunweaver at debian.org
Fri Nov 30 20:57:39 GMT 2018


Mike Gabriel pushed to branch master at Debian Security Tracker / security-tracker


Commits:
edef6f59 by Mike Gabriel at 2018-11-30T20:57:23Z
[libav LTS triaging] data/CVE/list: Tag CVE-2015-8217 for libav in jessie with <not-affected>.

- - - - -


2 changed files:

- data/CVE/list
- data/dla-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -140046,6 +140046,7 @@ CVE-2015-8217 (The ff_hevc_parse_sps function in libavcodec/hevc_ps.c in FFmpeg
 	[squeeze] - ffmpeg <not-affected> (Vulnerable code not present)
 	- libav <undetermined>
 	[wheezy] - libav <not-affected> (Vulnerable code not present)
+	[jessie] - libav <not-affected> (Contains a similar code block like the one referenced by the ffmpeg commit)
 	NOTE: https://git.videolan.org/?p=ffmpeg.git;a=commit;h=93f30f825c08477fe8f76be00539e96014cc83c8
 CVE-2015-8216 (The ljpeg_decode_yuv_scan function in libavcodec/mjpegdec.c in FFmpeg ...)
 	- ffmpeg 7:2.8.2-1


=====================================
data/dla-needed.txt
=====================================
@@ -36,6 +36,7 @@ libav (Markus Koschany, Mike Gabriel)
   NOTE: 20181130: CVE-2015-6825: patch available, issue untested (no PoC), vulnerable
   NOTE: 20181130: CVE-2015-6826: patch available, issue untested (no PoC), vulnerable
   NOTE: 20181130: CVE-2015-8216, patch available (does not apply cleanly), issue untested (no PoC), vulnerable
+  NOTE: 20181130: CVE-2015-8217: similar patch applied, issue untested, not-affected (@apo: please double-check)
 --
 libsndfile (Hugo Lefeuvre)
   NOTE: 20181123: CVE-2018-19432 minor but several older CVEs triaged no-dsa (such as CVE-2017-8361)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/edef6f59505a01405d1ff35fbff01e055c68e9d2

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/edef6f59505a01405d1ff35fbff01e055c68e9d2
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20181130/3f768aea/attachment-0001.html>


More information about the debian-security-tracker-commits mailing list