[Git][security-tracker-team/security-tracker][master] new libde265 issues

Moritz Muehlenhoff (@jmm) jmm at debian.org
Fri Sep 17 09:46:30 BST 2021



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
9fb8c88b by Moritz Muehlenhoff at 2021-09-17T10:46:12+02:00
new libde265 issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -77841,31 +77841,44 @@ CVE-2020-21608
 CVE-2020-21607
 	RESERVED
 CVE-2020-21606 (libde265 v1.0.4 contains a heap buffer overflow fault in the put_epel_ ...)
-	TODO: check
+	- libde265 <unfixed>
+	NOTE: https://github.com/strukturag/libde265/issues/232
 CVE-2020-21605 (libde265 v1.0.4 contains a segmentation fault in the apply_sao_interna ...)
-	TODO: check
+	- libde265 <unfixed>
+	NOTE: https://github.com/strukturag/libde265/issues/234
 CVE-2020-21604 (libde265 v1.0.4 contains a heap buffer overflow fault in the _mm_loadl ...)
-	TODO: check
+	- libde265 <unfixed>
+	NOTE: https://github.com/strukturag/libde265/issues/231
 CVE-2020-21603 (libde265 v1.0.4 contains a heap buffer overflow in the put_qpel_0_0_fa ...)
-	TODO: check
+	- libde265 <unfixed>
+	NOTE: https://github.com/strukturag/libde265/issues/240
 CVE-2020-21602 (libde265 v1.0.4 contains a heap buffer overflow in the put_weighted_bi ...)
-	TODO: check
+	- libde265 <unfixed>
+	NOTE: https://github.com/strukturag/libde265/issues/242
 CVE-2020-21601 (libde265 v1.0.4 contains a stack buffer overflow in the put_qpel_fallb ...)
-	TODO: check
+	- libde265 <unfixed>
+	NOTE: https://github.com/strukturag/libde265/issues/241
 CVE-2020-21600 (libde265 v1.0.4 contains a heap buffer overflow in the put_weighted_pr ...)
-	TODO: check
+	- libde265 <unfixed>
+	NOTE: https://github.com/strukturag/libde265/issues/243
 CVE-2020-21599 (libde265 v1.0.4 contains a heap buffer overflow in the de265_image::av ...)
-	TODO: check
+	- libde265 <unfixed>
+	NOTE: https://github.com/strukturag/libde265/issues/235
 CVE-2020-21598 (libde265 v1.0.4 contains a heap buffer overflow in the ff_hevc_put_unw ...)
-	TODO: check
+	- libde265 <unfixed>
+	NOTE: https://github.com/strukturag/libde265/issues/237
 CVE-2020-21597 (libde265 v1.0.4 contains a heap buffer overflow in the mc_chroma funct ...)
-	TODO: check
+	- libde265 <unfixed>
+	NOTE: https://github.com/strukturag/libde265/issues/238
 CVE-2020-21596 (libde265 v1.0.4 contains a global buffer overflow in the decode_CABAC_ ...)
-	TODO: check
+	- libde265 <unfixed>
+	NOTE: https://github.com/strukturag/libde265/issues/236
 CVE-2020-21595 (libde265 v1.0.4 contains a heap buffer overflow in the mc_luma functio ...)
-	TODO: check
+	- libde265 <unfixed>
+	NOTE: https://github.com/strukturag/libde265/issues/239
 CVE-2020-21594 (libde265 v1.0.4 contains a heap buffer overflow in the put_epel_hv_fal ...)
-	TODO: check
+	- libde265 <unfixed>
+	NOTE: https://github.com/strukturag/libde265/issues/233
 CVE-2020-21593
 	RESERVED
 CVE-2020-21592



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/9fb8c88b6a7a5ba663f601ba940e4f972b4664f0

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/9fb8c88b6a7a5ba663f601ba940e4f972b4664f0
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20210917/bedbd6ba/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list