libde265 (1.0.11-1+deb12u1) bookworm; urgency=medium
authorThorsten Alteholz <debian@alteholz.de>
Sun, 26 Nov 2023 12:03:02 +0000 (13:03 +0100)
committerThorsten Alteholz <debian@alteholz.de>
Sun, 26 Nov 2023 12:03:02 +0000 (13:03 +0100)
commit243aca22b86cfaef35a1cfd3bdb846599764a5d5
tree82a1aa3851aa42b2e47c611c04aca49d2bf86c2c
parent8da2b66b4b3b4c52f657a5ab455b0e3d4f0aa389
parentf9a0abdffe7e6ffc8e1c210c53d92516df51708b
libde265 (1.0.11-1+deb12u1) bookworm; urgency=medium

  * Non-maintainer upload by the LTS Team.
  * CVE-2023-27102 (Closes: #1033257)
    fix segmentation violation in the
    function decoder_context::process_slice_segment_header
  * CVE-2023-27103
    fix heap buffer overflow in the
    function derive_collocated_motion_vectors
  * CVE-2023-43887
    fix buffer over-read in pic_parameter_set::dump
  * CVE-2023-47471 (Closes: #1056187)
    fix buffer overflow in the slice_segment_header function

[dgit import unpatched libde265 1.0.11-1+deb12u1]
25 files changed:
debian/.gitlab-ci.yml
debian/changelog
debian/control
debian/copyright
debian/gbp.conf
debian/libde265-0.install
debian/libde265-0.symbols
debian/libde265-dev.docs
debian/libde265-dev.install
debian/libde265-examples.install
debian/not-installed
debian/patches/CVE-2023-27102.patch
debian/patches/CVE-2023-27103.patch
debian/patches/CVE-2023-43887.patch
debian/patches/CVE-2023-47471.patch
debian/patches/disable_tools.patch
debian/patches/only_export_decoder_api.patch
debian/patches/recycle_sps_if_possible.patch
debian/patches/reject_reference_pics_from_different_sps.patch
debian/patches/series
debian/patches/use_sps_from_the_image.patch
debian/rules
debian/source/format
debian/upstream/metadata
debian/watch