gst-plugins-bad1.0 (1.14.4-1+deb10u2) buster-security; urgency=high
authorSebastian Dröge <slomo@debian.org>
Thu, 22 Apr 2021 18:38:06 +0000 (19:38 +0100)
committerSebastian Dröge <slomo@debian.org>
Thu, 22 Apr 2021 18:38:06 +0000 (19:38 +0100)
commit20a96d5e9e68335553479b9d4f4a68715be20805
tree216953ddc460a14d8dab09ac0295383005ad74ad
parent56893dd678861bb9ab58ba824e8dce275dc1e9f2
parent55ec46d9972ba31ea54f9536745ced7d305775b1
gst-plugins-bad1.0 (1.14.4-1+deb10u2) buster-security; urgency=high

  * debian/patches/0001-h2645parser-Catch-overflows-in-AVC-HEVC-NAL-unit-length.patch:
    + Catch overflows in AVC/HEVC NAL unit length calculations, which would
      lead to allocating infinite amounts of small memory blocks until OOM and
      could potentially also lead to memory corruptions.

      See https://gitlab.freedesktop.org/gstreamer/gst-plugins-bad/-/merge_requests/2103

[dgit import unpatched gst-plugins-bad1.0 1.14.4-1+deb10u2]
27 files changed:
debian/HACKING.Debian
debian/README.Debian
debian/build-deps
debian/build-deps.in
debian/changelog
debian/compat
debian/control
debian/control.in
debian/copyright
debian/gbp.conf
debian/gir1.2-gst-plugins-bad.install
debian/gstreamer-opencv.install
debian/gstreamer-plugins-bad-doc.install
debian/gstreamer-plugins-bad.install
debian/libgstreamer-opencv.install
debian/libgstreamer-plugins-bad-dev.install
debian/libgstreamer-plugins-bad.install
debian/maint
debian/mk.control
debian/patches/0001-h2645parser-Catch-overflows-in-AVC-HEVC-NAL-unit-length.patch
debian/patches/01_fix-modplug-linking.patch
debian/patches/02_ref_pic_markings_overflow.patch
debian/patches/03_openexr-std-cxx11.patch
debian/patches/series
debian/rules
debian/source/format
debian/watch