Bug#550442: ffmpeg: deluge of crashes due to missing input sanitization

Marc Deslauriers marc.deslauriers at canonical.com
Thu Oct 29 18:53:13 UTC 2009


On Thu, 2009-10-15 at 13:03 +0200, Reinhard Tartler wrote:

<snip>

> of chromium patches and managed to locate most patches in ffmpeg trunk
> 
> Patches that I couldn't find upstream include:
> 
> 09_mov_stsz_int_oflow.patch
> 32_mov_stream_index.patch
> 35_mov_bad_timings.patch
> 40_ogg_missing_header.patch
> 
> They probably need further investigation.


09_mov_stsz_int_oflow.patch:

This looks like:
http://git.ffmpeg.org/?p=ffmpeg;a=commit;h=59a7d76f26091bb379e41e546c561d6987b2df3b

32_mov_stream_index.patch:

http://git.ffmpeg.org/?p=ffmpeg;a=commit;h=83b7e34ccb8f63f24d91dfc4dd89a4971f36ce12
http://git.ffmpeg.org/?p=ffmpeg;a=commit;h=b601744633167a1b37bc171d298872d57522400e

40_ogg_missing_header.patch:

http://git.ffmpeg.org/?p=ffmpeg;a=commit;h=7fb2fe280374bcb1c41c2a8e7aa5632d18dc4279


Marc.







More information about the pkg-multimedia-maintainers mailing list