[Git][security-tracker-team/security-tracker][master] [libav LTS triaging] data/CVE/list: Tag CVE-2016-10191 for libav in jessie as…
    Mike Gabriel 
    sunweaver at debian.org
       
    Fri Nov 30 22:30:23 GMT 2018
    
    
  
Mike Gabriel pushed to branch master at Debian Security Tracker / security-tracker
Commits:
59868a29 by Mike Gabriel at 2018-11-30T22:30:01Z
[libav LTS triaging] data/CVE/list: Tag CVE-2016-10191 for libav in jessie as vulnerable (i.e. <undetermined> -> <removed>).
- - - - -
2 changed files:
- data/CVE/list
- data/dla-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -92394,7 +92394,7 @@ CVE-2016-10192 (Heap-based buffer overflow in ffserver.c in FFmpeg before 2.8.10
 	NOTE: http://www.openwall.com/lists/oss-security/2017/01/31/12
 CVE-2016-10191 (Heap-based buffer overflow in libavformat/rtmppkt.c in FFmpeg before ...)
 	- ffmpeg 7:3.2.2-1
-	- libav <undetermined>
+	- libav <removed>
 	NOTE: Patch: https://github.com/FFmpeg/FFmpeg/commit/7d57ca4d9a75562fa32e40766211de150f8b3ee7
 	NOTE: http://www.openwall.com/lists/oss-security/2017/01/31/12
 CVE-2016-10190 (Heap-based buffer overflow in libavformat/http.c in FFmpeg before ...)
=====================================
data/dla-needed.txt
=====================================
@@ -44,6 +44,7 @@ libav (Markus Koschany, Mike Gabriel)
   NOTE: 20181130: CVE-2015-8662: patch available, issue untested (no PoC), vulnerable
   NOTE: 20181130: CVE-2015-8663: patch available (needs manual work), issue untested (no PoC), vulnerable
   NOTE: 20181130: CVE-2016-10190: patch available (might need manual work), issue untested (no PoC), vulnerable
+  NOTE: 20181130: CVE-2016-10191: patch available, issue untested (no PoC), vulnerable
 --
 libsndfile (Hugo Lefeuvre)
   NOTE: 20181123: CVE-2018-19432 minor but several older CVEs triaged no-dsa (such as CVE-2017-8361)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/59868a295f93d64be1b3fa3478ac34497aaf774a
-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/59868a295f93d64be1b3fa3478ac34497aaf774a
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20181130/e815a3ec/attachment.html>
    
    
More information about the debian-security-tracker-commits
mailing list