[Git][security-tracker-team/security-tracker][master] [libav LTS triaging] data/CVE/list: Tag CVE-2015-8364 for libav in jessie as…
Mike Gabriel
sunweaver at debian.org
Fri Nov 30 21:20:14 GMT 2018
Mike Gabriel pushed to branch master at Debian Security Tracker / security-tracker
Commits:
a1b28dce by Mike Gabriel at 2018-11-30T21:19:49Z
[libav LTS triaging] data/CVE/list: Tag CVE-2015-8364 for libav in jessie as vulnerable (i.e. <undetermined> -> <removed>).
- - - - -
2 changed files:
- data/CVE/list
- data/dla-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -139570,7 +139570,7 @@ CVE-2015-8365 (The smka_decode_frame function in libavcodec/smacker.c in FFmpeg
CVE-2015-8364 (Integer overflow in the ff_ivi_init_planes function in ...)
- ffmpeg 7:2.8.3-1 (bug #806519)
[squeeze] - ffmpeg <end-of-life> (Not supported in Squeeze LTS)
- - libav <undetermined>
+ - libav <removed>
NOTE: http://git.videolan.org/?p=ffmpeg.git;a=commit;h=df91aa034b82b77a3c4e01791f4a2b2ff6c82066
CVE-2015-8363 (The jpeg2000_read_main_headers function in libavcodec/jpeg2000dec.c in ...)
- ffmpeg 7:2.8.3-1 (bug #806519)
=====================================
data/dla-needed.txt
=====================================
@@ -39,6 +39,7 @@ libav (Markus Koschany, Mike Gabriel)
NOTE: 20181130: CVE-2015-8217: similar patch applied, issue untested, not-affected (@apo: please double-check)
NOTE: 20181130: CVE-2015-8219: patch available, issue untested (no PoC), vulnerable
NOTE: 20181130: CVE-2015-8363: patch available, issue untested (no PoC), vulnerable
+ NOTE: 20181130: CVE-2015-8364: patch available, issue untested (no PoC), vulnerable
--
libsndfile (Hugo Lefeuvre)
NOTE: 20181123: CVE-2018-19432 minor but several older CVEs triaged no-dsa (such as CVE-2017-8361)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/a1b28dcec18bc7918a166df8660dbd17ca33e308
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/a1b28dcec18bc7918a166df8660dbd17ca33e308
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20181130/bd9b9057/attachment.html>
More information about the debian-security-tracker-commits
mailing list