[Git][security-tracker-team/security-tracker][master] two ffmpeg upstream fixes

Moritz Muehlenhoff (@jmm) jmm at debian.org
Mon Apr 22 14:19:51 BST 2024



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
7b37837d by Moritz Muehlenhoff at 2024-04-22T15:19:16+02:00
two ffmpeg upstream fixes

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -317,15 +317,19 @@ CVE-2024-1065 (Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver
 CVE-2024-0671 (Use After Free vulnerability in Arm Ltd Midgard GPU Kernel Driver, Arm ...)
 	NOT-FOR-US: Arm
 CVE-2023-51798 (Buffer Overflow vulnerability in Ffmpeg v.N113007-g8d24a28d06 allows a ...)
+	[experimental] - ffmpeg 7:7.0-1
 	- ffmpeg <unfixed>
 	[bookworm] - ffmpeg <postponed> (Pick up when fixed in 5.1.x)
 	[bullseye] - ffmpeg <postponed> (Pick up when fixed in 4.3.x)
 	NOTE: https://trac.ffmpeg.org/ticket/10758
+	NOTE: Fixed in https://github.com/ffmpeg/FFmpeg/commit/68146f06f852078866b3ef1564556e3a272920c7 (n7.0)
 CVE-2023-51797 (Buffer Overflow vulnerability in Ffmpeg v.N113007-g8d24a28d06 allows a ...)
+	[experimental] - ffmpeg 7:7.0-1
 	- ffmpeg <unfixed>
 	[bookworm] - ffmpeg <postponed> (Pick up when fixed in 5.1.x)
 	[bullseye] - ffmpeg <postponed> (Pick up when fixed in 4.3.x)
 	NOTE: https://trac.ffmpeg.org/ticket/10756
+	NOTE: Fixed in https://github.com/ffmpeg/FFmpeg/commit/08bd2cbfeb34717d60ec62bcbaeb7996206df906 (n7.0)
 CVE-2023-51796 (Buffer Overflow vulnerability in Ffmpeg v.N113007-g8d24a28d06 allows a ...)
 	[experimental] - ffmpeg 7:7.0-1
 	- ffmpeg <unfixed>



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/7b37837d0851441d45e55aef3a51393dddfe5347

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/7b37837d0851441d45e55aef3a51393dddfe5347
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20240422/17c165f7/attachment.htm>


More information about the debian-security-tracker-commits mailing list