[Git][security-tracker-team/security-tracker][master] 2 commits: [libav LTS triaging] data/CVE/list: Tag CVE-2015-8661 for libav in jessie as…

Mike Gabriel sunweaver at debian.org
Fri Nov 30 21:42:52 GMT 2018


Mike Gabriel pushed to branch master at Debian Security Tracker / security-tracker


Commits:
7f1f0916 by Mike Gabriel at 2018-11-30T21:32:40Z
[libav LTS triaging] data/CVE/list: Tag CVE-2015-8661 for libav in jessie as vulnerable (i.e. <undetermined> -> <removed>).

- - - - -
9e3eb491 by Mike Gabriel at 2018-11-30T21:41:41Z
[libav LTS triaging] data/CVE/list: Tag CVE-2015-8662 for libav in jessie as vulnerable (i.e. <undetermined> -> <removed>).

- - - - -


2 changed files:

- data/CVE/list
- data/dla-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -135762,13 +135762,13 @@ CVE-2015-8663 (The ff_get_buffer function in libavcodec/utils.c in FFmpeg before
 CVE-2015-8662 (The ff_dwt_decode function in libavcodec/jpeg2000dwt.c in FFmpeg ...)
 	- ffmpeg 7:2.8.4-1
 	[squeeze] - ffmpeg <end-of-life> (Not supported in Squeeze LTS)
-	- libav <undetermined>
+	- libav <removed>
 	[wheezy] - libav <not-affected> (Vulnerable code not present)
 	NOTE: http://git.videolan.org/?p=ffmpeg.git;a=commit;h=75422280fbcdfbe9dc56bde5525b4d8b280f1bc5
 CVE-2015-8661 (The h264_slice_header_init function in libavcodec/h264_slice.c in ...)
 	- ffmpeg 7:2.8.3-1
 	[squeeze] - ffmpeg <end-of-life> (Not supported in Squeeze LTS)
-	- libav <undetermined>
+	- libav <removed>
 	NOTE: http://git.videolan.org/?p=ffmpeg.git;a=commit;h=4ea4d2f438c9a7eba37980c9a87be4b34943e4d5
 CVE-2015-8658 (Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before ...)
 	NOT-FOR-US: Adobe Flash Player


=====================================
data/dla-needed.txt
=====================================
@@ -40,6 +40,8 @@ libav (Markus Koschany, Mike Gabriel)
   NOTE: 20181130: CVE-2015-8219: patch available, issue untested (no PoC), vulnerable
   NOTE: 20181130: CVE-2015-8363: patch available, issue untested (no PoC), vulnerable
   NOTE: 20181130: CVE-2015-8364: patch available, issue untested (no PoC), vulnerable
+  NOTE: 20181130: CVE-2015-8661: patch available, issue untested (no PoC), vulnerable
+  NOTE: 20181130: CVE-2015-8662: patch available, issue untested (no PoC), vulnerable
 --
 libsndfile (Hugo Lefeuvre)
   NOTE: 20181123: CVE-2018-19432 minor but several older CVEs triaged no-dsa (such as CVE-2017-8361)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/compare/ca75fa5cea276d75e713887872e12029fd194529...9e3eb491a05caa3fc3b7deebb281a4b7a3cd1507

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/compare/ca75fa5cea276d75e713887872e12029fd194529...9e3eb491a05caa3fc3b7deebb281a4b7a3cd1507
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20181130/a43bb300/attachment.html>


More information about the debian-security-tracker-commits mailing list