gst-plugins-bad1.0 (1.14.4-1+deb10u4) buster-security; urgency=high
authorThorsten Alteholz <debian@alteholz.de>
Fri, 27 Oct 2023 20:55:02 +0000 (22:55 +0200)
committerThorsten Alteholz <debian@alteholz.de>
Fri, 27 Oct 2023 20:55:02 +0000 (22:55 +0200)
commit083424d5ed559b961ec74e7bbc6c40a24286cf31
treed8d97356f6cba08c200b74e63621a880a810bd1e
parentb739ef2b85a318618d4b695540af1ccb43855672
parentc2f84828ebe93bb0e5d55ac28dcde27f49b26987
gst-plugins-bad1.0 (1.14.4-1+deb10u4) buster-security; urgency=high

  * Non-maintainer upload by the LTS Team.
  * CVE-2023-40476
    h265parser: Fix possible overflow using max_sub_layers_minus1
  * CVE-2023-40475
    mxfdemux: Check number of channels for AES3 audio (CVE-2023-40475)
  * CVE-2023-40474
    mxfdemux: Fix integer overflow causing out of bounds writes when handling
    invalid uncompressed video

[dgit import unpatched gst-plugins-bad1.0 1.14.4-1+deb10u4]
31 files changed:
debian/HACKING.Debian
debian/README.Debian
debian/build-deps
debian/build-deps.in
debian/changelog
debian/compat
debian/control
debian/control.in
debian/copyright
debian/gbp.conf
debian/gir1.2-gst-plugins-bad.install
debian/gstreamer-opencv.install
debian/gstreamer-plugins-bad-doc.install
debian/gstreamer-plugins-bad.install
debian/libgstreamer-opencv.install
debian/libgstreamer-plugins-bad-dev.install
debian/libgstreamer-plugins-bad.install
debian/maint
debian/mk.control
debian/patches/0001-h2645parser-Catch-overflows-in-AVC-HEVC-NAL-unit-length.patch
debian/patches/01_fix-modplug-linking.patch
debian/patches/02_ref_pic_markings_overflow.patch
debian/patches/03_openexr-std-cxx11.patch
debian/patches/CVE-2023-40474.patch
debian/patches/CVE-2023-40475.patch
debian/patches/CVE-2023-40476.patch
debian/patches/SA-2023-0003.patch
debian/patches/series
debian/rules
debian/source/format
debian/watch