[Git][security-tracker-team/security-tracker][master] LTS: CVE-2020-35964/ffmpeg mark as <not-affected> for stretch

Roberto C. Sánchez roberto at debian.org
Sun Jan 31 01:02:26 GMT 2021



Roberto C. Sánchez pushed to branch master at Debian Security Tracker / security-tracker


Commits:
529c47f8 by Roberto C. Sánchez at 2021-01-30T20:02:00-05:00
LTS: CVE-2020-35964/ffmpeg mark as <not-affected> for stretch

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -11286,6 +11286,7 @@ CVE-2020-35965 (decode_frame in libavcodec/exr.c in FFmpeg 4.3.1 has an out-of-b
 CVE-2020-35964 (track_header in libavformat/vividas.c in FFmpeg 4.3.1 has an out-of-bo ...)
 	- ffmpeg 7:4.3.1-6 (bug #980000)
 	[buster] - ffmpeg <postponed> (Wait for 4.1.7)
+	[stretch] - ffmpeg <not-affected> (Vulnerable code introduced later)
 	NOTE: https://github.com/FFmpeg/FFmpeg/commit/27a99e2c7d450fef15594671eef4465c8a166bd7
 	NOTE: https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=26622
 CVE-2020-35963 (flb_gzip_compress in flb_gzip.c in Fluent Bit before 1.6.4 has an out- ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/529c47f897de07551fcc5ebf51a517fc15b26289

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/529c47f897de07551fcc5ebf51a517fc15b26289
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20210131/c4d1750f/attachment.html>


More information about the debian-security-tracker-commits mailing list