Bug#775593: Available fixes for some of the issues

Moritz Muehlenhoff jmm at inutil.org
Tue Jan 20 16:07:05 UTC 2015


> Five CVEs therefore remain without upstream patches in libav:
> 
> https://security-tracker.debian.org/tracker/CVE-2014-8544
> https://security-tracker.debian.org/tracker/CVE-2014-8546
> https://security-tracker.debian.org/tracker/CVE-2014-9316
> https://security-tracker.debian.org/tracker/CVE-2014-9318
> https://security-tracker.debian.org/tracker/CVE-2014-9319 

Hi,
in addition these three issues are a still open:
https://security-tracker.debian.org/tracker/CVE-2014-9603
https://security-tracker.debian.org/tracker/CVE-2014-9604

use after free in seg_write_packet() (no CVE yet):
http://www.openwall.com/lists/oss-security/2015/01/04/10
https://git.videolan.org/?p=ffmpeg.git;a=commitdiff;h=169065fbfb3da1ab776379c333aebc54bb1f1bc4

Cheers,
        Moritz



More information about the pkg-multimedia-maintainers mailing list