[Git][security-tracker-team/security-tracker][master] [libav LTS triaging] data/CVE/list: Work on CVE-2016-10192 and CVE-2016-5115.…
Mike Gabriel
sunweaver at debian.org
Fri Nov 30 23:09:21 GMT 2018
Mike Gabriel pushed to branch master at Debian Security Tracker / security-tracker
Commits:
575156db by Mike Gabriel at 2018-11-30T23:09:09Z
[libav LTS triaging] data/CVE/list: Work on CVE-2016-10192 and CVE-2016-5115. Calling it a day for today.
- - - - -
2 changed files:
- data/CVE/list
- data/dla-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -92386,7 +92386,7 @@ CVE-2016-XXXX [iio-sensor-proxy: insecure dbus policy]
- iio-sensor-proxy 2.0-4 (bug #853951)
CVE-2016-10192 (Heap-based buffer overflow in ffserver.c in FFmpeg before 2.8.10, ...)
- ffmpeg 7:3.2.2-1
- - libav <undetermined>
+ - libav <not-affected> (Vulnerable code not present in libav, only in ffmpeg)
NOTE: Patch: https://github.com/FFmpeg/FFmpeg/commit/a5d25faa3f4b18dac737fdb35d0dd68eb0dc2156
NOTE: http://www.openwall.com/lists/oss-security/2017/01/31/12
CVE-2016-10191 (Heap-based buffer overflow in libavformat/rtmppkt.c in FFmpeg before ...)
=====================================
data/dla-needed.txt
=====================================
@@ -35,7 +35,7 @@ libav (Markus Koschany, Mike Gabriel)
NOTE: 20181130: CVE-2015-6824: patch available, issue untested (no PoC), vulnerable
NOTE: 20181130: CVE-2015-6825: patch available, issue untested (no PoC), vulnerable
NOTE: 20181130: CVE-2015-6826: patch available, issue untested (no PoC), vulnerable
- NOTE: 20181130: CVE-2015-8216, patch available (does not apply cleanly), issue untested (no PoC), vulnerable
+ NOTE: 20181130: CVE-2015-8216: patch available (does not apply cleanly), issue untested (no PoC), vulnerable
NOTE: 20181130: CVE-2015-8217: similar patch applied, issue untested, not-affected (@apo: please double-check)
NOTE: 20181130: CVE-2015-8219: patch available, issue untested (no PoC), vulnerable
NOTE: 20181130: CVE-2015-8363: patch available, issue untested (no PoC), vulnerable
@@ -45,6 +45,8 @@ libav (Markus Koschany, Mike Gabriel)
NOTE: 20181130: CVE-2015-8663: patch available (needs manual work), issue untested (no PoC), vulnerable
NOTE: 20181130: CVE-2016-10190: patch available (might need manual work), issue untested (no PoC), vulnerable
NOTE: 20181130: CVE-2016-10191: patch available, issue untested (no PoC), vulnerable
+ NOTE: 20181130: CVE-2016-10192: vulnerable code not present (only in ffmpeg)
+ NOTE: 20181130: CVE-2016-5115: patch unavailable (needs revisiting), issue reproducible, no-dsa (needs revisiting)
--
libsndfile (Hugo Lefeuvre)
NOTE: 20181123: CVE-2018-19432 minor but several older CVEs triaged no-dsa (such as CVE-2017-8361)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/575156dba4223dc1502ed60e387780bd4c0619c2
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/575156dba4223dc1502ed60e387780bd4c0619c2
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20181130/51989c38/attachment.html>
More information about the debian-security-tracker-commits
mailing list