[Git][security-tracker-team/security-tracker][master] Add CVE-2025-7700/ffmpeg
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Fri Jul 18 06:41:38 BST 2025
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
fe62192c by Salvatore Bonaccorso at 2025-07-18T07:39:36+02:00
Add CVE-2025-7700/ffmpeg
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,3 +1,9 @@
+CVE-2025-7700 [NULL Pointer Dereference in FFmpeg ALS Decoder (libavcodec/alsdec.c)]
+ - ffmpeg <unfixed>
+ [trixie] - ffmpeg <postponed> (Minor issue, wait until it's fixed in the 7.1 branch)
+ [bookworm] - ffmpeg <postponed> (Minor issue, wait until it's fixed in the 5.1 branch)
+ NOTE: Introduced with: https://git.ffmpeg.org/gitweb/ffmpeg.git/object/dcfd24b10c7eaec4b7b1ec2c4abb46808721a71d
+ NOTE: Fixed by: https://git.ffmpeg.org/gitweb/ffmpeg.git/commitdiff/35a6de137a39f274d5e01ed0e0e6c4f04d0aaf07
CVE-2025-40924 [generates session ids insecurely]
- libcatalyst-plugin-session-perl <unfixed> (bug #1109439)
[bookworm] - libcatalyst-plugin-session-perl <no-dsa> (Minor issue)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/fe62192ca87baec89309f8ecfc4faede7fdaf5db
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/fe62192ca87baec89309f8ecfc4faede7fdaf5db
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20250718/e14e2cf5/attachment.htm>
More information about the debian-security-tracker-commits
mailing list