[Git][security-tracker-team/security-tracker][master] Add CVE-2020-23906/ffmpeg
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Thu Nov 11 20:24:47 GMT 2021
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
eff053c1 by Salvatore Bonaccorso at 2021-11-11T21:24:20+01:00
Add CVE-2020-23906/ffmpeg
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -81549,7 +81549,12 @@ CVE-2020-23908
CVE-2020-23907 (An issue was discovered in retdec v3.3. In function canSplitFunctionOn ...)
NOT-FOR-US: retdec
CVE-2020-23906 (FFmpeg N-98388-g76a3ee996b allows attackers to cause a denial of servi ...)
- TODO: check
+ - ffmpeg 7:4.3.1-1
+ [buster] - ffmpeg <not-affected> (Vulnerable code introduced later)
+ [stretch] - ffmpeg <not-affected> (Vulnerable code introduced later)
+ NOTE: Regressed since: http://git.videolan.org/?p=ffmpeg.git;a=commitdiff;h=e045be92cdf5a2851900e8e85b815c29ae6f100a (n4.3)
+ NOTE: Fixed by: http://git.videolan.org/?p=ffmpeg.git;a=commitdiff;h=ec59dc73f0cc8930bf5dae389cd76d049d537ca7 (n4.4)
+ NOTE: Fixed by: http://git.videolan.org/?p=ffmpeg.git;a=commitdiff;h=be84216c53a4ed81573c82320e9c4a20e9b349d9 (n4.3.1)
CVE-2020-23905
RESERVED
CVE-2020-23904 (A stack buffer overflow in speexenc.c of Speex v1.2 allows attackers t ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/eff053c1e0f507a244e71efc40b6466cb642dfbb
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/eff053c1e0f507a244e71efc40b6466cb642dfbb
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20211111/d7e8afc2/attachment.htm>
More information about the debian-security-tracker-commits
mailing list