[Git][security-tracker-team/security-tracker][master] CVE-2020-20902/ffmpeg: fixed through DLA-3010-1

Sylvain Beucler (@beuc) beuc at debian.org
Mon May 23 14:05:39 BST 2022



Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker


Commits:
e4353990 by Sylvain Beucler at 2022-05-23T15:05:21+02:00
CVE-2020-20902/ffmpeg: fixed through DLA-3010-1

- - - - -


2 changed files:

- data/CVE/list
- data/DLA/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -126991,13 +126991,15 @@ CVE-2020-20903
 CVE-2020-20902 (A CWE-125: Out-of-bounds read vulnerability exists in long_term_filter ...)
 	{DSA-4722-1}
 	- ffmpeg 7:4.2.2-1
-	[stretch] - ffmpeg <postponed> (Minor issue; can be fixed in next update)
 	NOTE: https://trac.ffmpeg.org/ticket/8176
 	NOTE: http://git.videolan.org/?p=ffmpeg.git;a=commitdiff;h=5f0acc5064ed501cb40d4aaccae2b3ce5c4552fd (4.3)
 	NOTE: http://git.videolan.org/?p=ffmpeg.git;a=commitdiff;h=2c78a76cb0443f8a12a5eadc3b58373aa2f4ab22 (4.3)
 	NOTE: http://git.videolan.org/?p=ffmpeg.git;a=commitdiff;h=b97aaf791f6ea3506a6252ecef6a1a0e9a542e04 (4.2.2)
 	NOTE: http://git.videolan.org/?p=ffmpeg.git;a=commitdiff;h=81672bf00f3b5a3c025034f4b2e33d67b72f3839 (4.2.2)
 	NOTE: http://git.videolan.org/?p=ffmpeg.git;a=commitdiff;h=a0c91fb0f0641f9f35f650281a176657907097cf (4.1.5)
+	NOTE: http://git.videolan.org/?p=ffmpeg.git;a=commitdiff;h=abf9627f70ed8467b1646d56205e61f965f11468 (4.1.9)
+	NOTE: http://git.videolan.org/?p=ffmpeg.git;a=commitdiff;h=1cff89a11fa051696109565b3bf88c94479374eb (3.2.15)
+	NOTE: http://git.videolan.org/?p=ffmpeg.git;a=commitdiff;h=abf9627f70ed8467b1646d56205e61f965f11468 (3.2.17)
 CVE-2020-20901
 	REJECTED
 CVE-2020-20900


=====================================
data/DLA/list
=====================================
@@ -29,6 +29,7 @@
 	{CVE-2022-0261 CVE-2022-0351 CVE-2022-0413 CVE-2022-0443 CVE-2022-0572 CVE-2022-1154 CVE-2022-1616 CVE-2022-1619 CVE-2022-1621}
 	[stretch] - vim 2:8.0.0197-4+deb9u6
 [16 May 2022] DLA-3010-1 ffmpeg - security update
+	{CVE-2020-20902}
 	[stretch] - ffmpeg 7:3.2.18-0+deb9u1
 [16 May 2022] DLA-3009-1 cifs-utils - security update
 	{CVE-2022-27239 CVE-2022-29869}



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e43539900385b40beedb6bad656f72a8bf7cb8f4

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e43539900385b40beedb6bad656f72a8bf7cb8f4
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20220523/6ff385ec/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list