[Git][security-tracker-team/security-tracker][master] Add new ffmpeg issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Fri Nov 29 21:49:22 GMT 2024



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
f6641488 by Salvatore Bonaccorso at 2024-11-29T22:49:05+01:00
Add new ffmpeg issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -79,15 +79,20 @@ CVE-2024-36621 (moby v25.0.5 is affected by a Race Condition in builder/builder-
 CVE-2024-36620 (moby v25.0.0 - v26.0.2 is vulnerable to NULL Pointer Dereference via d ...)
 	TODO: check
 CVE-2024-36619 (FFmpeg n6.1.1 has a vulnerability in the WAVARC decoder of the libavco ...)
-	TODO: check
+	- ffmpeg 7:7.1-3
+	NOTE: https://github.com/ffmpeg/ffmpeg/commit/28c7094b25b689185155a6833caf2747b94774a4 (n7.1)
 CVE-2024-36618 (FFmpeg n6.1.1 has a vulnerability in the AVI demuxer of the libavforma ...)
-	TODO: check
+	- ffmpeg 7:7.0.1-3
+	NOTE: https://github.com/ffmpeg/ffmpeg/commit/7a089ed8e049e3bfcb22de1250b86f2106060857 (n7.0)
 CVE-2024-36617 (FFmpeg n6.1.1 has an integer overflow vulnerability in the FFmpeg CAF  ...)
-	TODO: check
+	- ffmpeg 7:7.0.1-3
+	NOTE: https://github.com/ffmpeg/ffmpeg/commit/d973fcbcc2f944752ff10e6a76b0b2d9329937a7 (n7.0)
 CVE-2024-36616 (An integer overflow in the component /libavformat/westwood_vqa.c of FF ...)
-	TODO: check
+	- ffmpeg 7:7.0.1-3
+	NOTE: https://github.com/ffmpeg/ffmpeg/commit/86f73277bf014e2ce36dd2594f1e0fb8b3bd6661 (n7.0)
 CVE-2024-36615 (FFmpeg n7.0 has a race condition vulnerability in the VP9 decoder. Thi ...)
-	TODO: check
+	- ffmpeg 7:7.1-3
+	NOTE: https://github.com/ffmpeg/ffmpeg/commit/0ba058579f332b3060d8470a04ddd3fbf305be61 (n7.1)
 CVE-2024-36612 (Zulip from 8.0 to 8.3 contains a memory leak vulnerability in the hand ...)
 	NOT-FOR-US: Zulip
 CVE-2024-36611 (In Symfony v7.07, a security vulnerability was identified in the FormL ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/f6641488d9455aca13480cde845190ca37b9effd

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/f6641488d9455aca13480cde845190ca37b9effd
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20241129/18106017/attachment.htm>


More information about the debian-security-tracker-commits mailing list