[Git][security-tracker-team/security-tracker][master] 2 commits: Add fixed version for CVE-2020-22016/ffmpeg via unstable

Salvatore Bonaccorso (@carnil) carnil at debian.org
Tue Jun 1 18:22:10 BST 2021



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
9637a506 by Salvatore Bonaccorso at 2021-06-01T19:17:44+02:00
Add fixed version for CVE-2020-22016/ffmpeg via unstable

- - - - -
088dc3db by Salvatore Bonaccorso at 2021-06-01T19:21:41+02:00
Adjust references for CVE-2020-22021

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -57794,9 +57794,9 @@ CVE-2020-22022 (A heap-based Buffer Overflow vulnerability exists in FFmpeg 4.2
 	NOTE: http://git.videolan.org/?p=ffmpeg.git;a=commitdiff;h=07050d7bdc32d82e53ee5bb727f5882323d00dba
 	NOTE: https://trac.ffmpeg.org/ticket/8264
 CVE-2020-22021 (Buffer Overflow vulnerability in FFmpeg 4.2 at filter_edges function i ...)
-	TODO: check
-	NOTE: http://git.videolan.org/?p=ffmpeg.git;a=commitdiff;h=
-	NOTE: https://trac.ffmpeg.org/ticket/
+	- ffmpeg <unfixed>
+	NOTE: https://lists.ffmpeg.org/pipermail/ffmpeg-devel/2021-May/280739.html
+	NOTE: https://trac.ffmpeg.org/ticket/8240
 CVE-2020-22020 (Buffer Overflow vulnerability in FFmpeg 4.2 in the build_diff_map func ...)
 	- ffmpeg 7:4.3-2
 	[buster] - ffmpeg <postponed> (Wait for 4.1.7)
@@ -57817,7 +57817,7 @@ CVE-2020-22017 (A heap-based Buffer Overflow vulnerability exists in FFmpeg 4.2
 	NOTE: https://trac.ffmpeg.org/ticket/8309
 	NOTE: http://git.videolan.org/?p=ffmpeg.git;a=commitdiff;h=d4d6b7b0355f3597cad3b8d12911790c73b5f96d
 CVE-2020-22016 (A heap-based Buffer Overflow vulnerability in FFmpeg 4.2 at libavcodec ...)
-	- ffmpeg <unfixed>
+	- ffmpeg 7:4.2.2-1
 	[buster] - ffmpeg <postponed> (Wait for 4.1.7)
 	NOTE: https://trac.ffmpeg.org/ticket/8183
 	NOTE: http://git.videolan.org/?p=ffmpeg.git;a=commitdiff;h=58aa0ed8f10753ee90f4a4a1f4f3da803cf7c145



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/6ef5cbb310bb646e50be129f03e8b1bd64f69093...088dc3db6a8a2ab592654808536f45bcade4c0eb

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/6ef5cbb310bb646e50be129f03e8b1bd64f69093...088dc3db6a8a2ab592654808536f45bcade4c0eb
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20210601/86fdb507/attachment.htm>


More information about the debian-security-tracker-commits mailing list