libav (6:11.11-1~deb8u1) jessie-security; urgency=medium
authorHugo Lefeuvre <hle@debian.org>
Sat, 21 Oct 2017 13:08:38 +0000 (14:08 +0100)
committerHugo Lefeuvre <hle@debian.org>
Sat, 21 Oct 2017 13:08:38 +0000 (14:08 +0100)
commit7923026719fcf2aa5939a6a2f645ac8754d3d9ba
tree6636f6c2baf4ec3eab8db8159faa6c509e74b8bd
parentae05c2d0511ac750c75806264dcfc62cba11ec69
parent68fdf7cab1caac9382e303fa2c754591ad899bd8
libav (6:11.11-1~deb8u1) jessie-security; urgency=medium

  * Non-maintainer upload by the Security Team.
  * New upstream release fixing multiple security issues.
    - dfa: Disallow odd width/height and add proper bounds check for DDS1 chunks
      (CVE-2017-9992)
    - pictor: Correctly check frame dimensions (CVE-2017-7862)
    - h264_cavlc: check the value of run_before
    - dvbsubdec: improve error checking
    - dvbsubdec: Fixed segfault when decoding subtitles
    - rmdec: don't ignore the return value of av_get_packet()
    - caf: add an Opus tag
    - yadif: Account for the buffer alignment while processing the frame edges
    - mov: log and return early on non-positive stsd entry counts
    - arm: Fix SIGBUS on ARM when compiled with binutils 2.29
    - smacker: return meaningful error codes on failure
    - smacker: fix integer overflow with pts_inc
    - mm: Skip unexpected audio packets
    - aacsbr: Turnoff in the event of over read.
    - smacker: Check that the data size is a multiple of a sample vector
      (CVE-2015-8365)
    - build: Add an option for passing linker flags to the shared library build
    - flv: Validate the packet size
    - mjpeg: Report non-3 component rgb lossless as not supported
    - vc1dec: raise an error if sprite picture data is missing
    - doc: Drop the legacy symlink to README

[dgit import unpatched libav 6:11.11-1~deb8u1]
51 files changed:
debian/NEWS
debian/README.Debian
debian/README.source
debian/changelog
debian/clean
debian/compat
debian/confflags
debian/control
debian/copyright
debian/gbp.conf
debian/get_soname_version.sh
debian/libav-doc.doc-base
debian/libav-tools.install
debian/libav-tools.maintscript
debian/libavcodec-dev.examples
debian/libavcodec-dev.install.in
debian/libavcodec-extra-56.install.in
debian/libavcodec-extra-56.lintian-overrides
debian/libavcodec56.install.in
debian/libavcodec56.lintian-overrides
debian/libavdevice-dev.install.in
debian/libavdevice55.install.in
debian/libavdevice55.lintian-overrides
debian/libavfilter-dev.install.in
debian/libavfilter5.install.in
debian/libavfilter5.lintian-overrides
debian/libavformat-dev.install.in
debian/libavformat56.install.in
debian/libavformat56.lintian-overrides
debian/libavresample-dev.install.in
debian/libavresample2.install.in
debian/libavresample2.lintian-overrides
debian/libavutil-dev.install.in
debian/libavutil54.install.in
debian/libavutil54.lintian-overrides
debian/libswscale-dev.install.in
debian/libswscale3.install.in
debian/libswscale3.lintian-overrides
debian/patches/02-configure-disable-ebx-gcc-4.9.patch
debian/patches/03-disable-configuration-warnings.patch
debian/patches/series
debian/qt-faststart.1
debian/rebuild-scripts/README
debian/rebuild-scripts/do_all_safe
debian/rebuild-scripts/git_experimental_source
debian/rules
debian/source/format
debian/source/include-binaries
debian/source/lintian-overrides
debian/upstream-signing-key.pgp
debian/watch