[Git][security-tracker-team/security-tracker][master] Update status for CVE-2025-59729/ffmpeg
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Sun Oct 19 13:26:26 BST 2025
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
ed27a4c4 by Salvatore Bonaccorso at 2025-10-19T14:25:45+02:00
Update status for CVE-2025-59729/ffmpeg
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -4404,10 +4404,9 @@ CVE-2025-59730 (When decoding a frame for a SANM file (ANIM v0 variant), the dec
NOTE: Introduced by: https://git.ffmpeg.org/gitweb/ffmpeg.git/commit/b22ce90d4228d1cb7727775cc848613ac31b97e9 (n8.0)
NOTE: Fixed by: https://git.ffmpeg.org/gitweb/ffmpeg.git/commit/3ccd7d8c8e85aaae0c6d6cc88ea6cb5309d56cdc (n8.0)
CVE-2025-59729 (When parsing the header for a DHAV file, there's an integer underflow ...)
- - ffmpeg <undetermined>
- TODO: check, too little information available, only product association from Google CNA
+ - ffmpeg <not-affected> (Vulnerable code not present)
NOTE: https://issuetracker.google.com/issues/433513232
- NOTE: Introduced in: https://git.ffmpeg.org/gitweb/ffmpeg.git/commit/36ec9217e6dca3432304c9d76078d9618247eb0f (8.0 series)
+ NOTE: Introduced in: https://git.ffmpeg.org/gitweb/ffmpeg.git/commit/36ec9217e6dca3432304c9d76078d9618247eb0f (n8.0)
NOTE: Fixed by: https://git.ffmpeg.org/gitweb/ffmpeg.git/commit/33ae6cda71e6d34c9081a612abae00e2c7d39f72 (n8.0)
CVE-2025-59728 (When calculating the content path in handling of MPEG-DASH manifests, ...)
NOT-FOR-US: MPEG-DASH
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ed27a4c4e3b22689cd5962174eb76213aabb5ce7
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ed27a4c4e3b22689cd5962174eb76213aabb5ce7
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20251019/9f04ee34/attachment.htm>
More information about the debian-security-tracker-commits
mailing list