[Git][security-tracker-team/security-tracker][master] [libav LTS triaging] data/CVE/list: Tag CVE-2015-8663 for libav in jessie as…

Mike Gabriel sunweaver at debian.org
Fri Nov 30 22:14:24 GMT 2018


Mike Gabriel pushed to branch master at Debian Security Tracker / security-tracker


Commits:
21eef501 by Mike Gabriel at 2018-11-30T22:13:48Z
[libav LTS triaging] data/CVE/list: Tag CVE-2015-8663 for libav in jessie as vulnerable (i.e. <undetermined> -> <removed>). Add comment on where to patch the libav code.

- - - - -


2 changed files:

- data/CVE/list
- data/dla-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -135757,8 +135757,9 @@ CVE-2015-8664 (Integer overflow in the WebCursor::Deserialize function in ...)
 CVE-2015-8663 (The ff_get_buffer function in libavcodec/utils.c in FFmpeg before ...)
 	- ffmpeg 7:2.8.4-1
 	[squeeze] - ffmpeg <end-of-life> (Not supported in Squeeze LTS)
-	- libav <undetermined>
+	- libav <removed>
 	NOTE: http://git.videolan.org/?p=ffmpeg.git;a=commit;h=abee0a1c60612e8638640a8a3738fffb65e16dbf
+	NOTE: For libav in jessie the patch needs to applied in libavcodec/decode.c in line 1884.
 CVE-2015-8662 (The ff_dwt_decode function in libavcodec/jpeg2000dwt.c in FFmpeg ...)
 	- ffmpeg 7:2.8.4-1
 	[squeeze] - ffmpeg <end-of-life> (Not supported in Squeeze LTS)


=====================================
data/dla-needed.txt
=====================================
@@ -42,6 +42,7 @@ libav (Markus Koschany, Mike Gabriel)
   NOTE: 20181130: CVE-2015-8364: patch available, issue untested (no PoC), vulnerable
   NOTE: 20181130: CVE-2015-8661: patch available, issue untested (no PoC), vulnerable
   NOTE: 20181130: CVE-2015-8662: patch available, issue untested (no PoC), vulnerable
+  NOTE: 20181130: CVE-2015-8663: patch available (needs manual work), issue untested (no PoC), vulnerable
 --
 libsndfile (Hugo Lefeuvre)
   NOTE: 20181123: CVE-2018-19432 minor but several older CVEs triaged no-dsa (such as CVE-2017-8361)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/21eef501c63dbb7110857887f9dc599fde123f2f

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/21eef501c63dbb7110857887f9dc599fde123f2f
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20181130/5392536e/attachment.html>


More information about the debian-security-tracker-commits mailing list