libde265.git
2 years ago[PATCH] Try to mitigate asan failures.
Tobias Frost [Mon, 12 Dec 2022 13:03:12 +0000 (14:03 +0100)]
[PATCH] Try to mitigate asan failures.

See #345 for my analysis and details…

(This PR is just for discussion.)

(The CVE references are obtained from the Debian security tracker,
which links the issues.)

This makes the following POCs stop failing:

- poc3 (#337)
- poc7-1 (#341) CVE-2022-43239 (note: does NOT fix poc7-2)
- poc8-2, poc8-3, poc8-4 (#342) CVE-2022-43244   (note: does NOT fix poc8-1)
- poc11-1, poc11-2 (#345) CVE-2022-43249
- poc12 (#346)
- poc13 (#347) CVE-2022-43252
- poc16 (#350)

Gbp-Pq: Name reject_reference_pics_from_different_sps.patch

2 years agoDisable building of some internal tools that no longer link
Joachim Bauch [Sun, 26 Nov 2023 12:03:02 +0000 (13:03 +0100)]
Disable building of some internal tools that no longer link

because internal symbols are no longer exported.

Gbp-Pq: Name disable_tools.patch

2 years agoOnly export symbols defined in the decoder API.
Joachim Bauch [Sun, 26 Nov 2023 12:03:02 +0000 (13:03 +0100)]
Only export symbols defined in the decoder API.

The encoder API is not final yet, so upstream exports all symbols to make
development easier. For packaging we only want to expose the public API.

Gbp-Pq: Name only_export_decoder_api.patch

2 years agolibde265 (1.0.11-1+deb12u1) bookworm; urgency=medium
Thorsten Alteholz [Sun, 26 Nov 2023 12:03:02 +0000 (13:03 +0100)]
libde265 (1.0.11-1+deb12u1) bookworm; urgency=medium

  * Non-maintainer upload by the LTS Team.
  * CVE-2023-27102 (Closes: #1033257)
    fix segmentation violation in the
    function decoder_context::process_slice_segment_header
  * CVE-2023-27103
    fix heap buffer overflow in the
    function derive_collocated_motion_vectors
  * CVE-2023-43887
    fix buffer over-read in pic_parameter_set::dump
  * CVE-2023-47471 (Closes: #1056187)
    fix buffer overflow in the slice_segment_header function

[dgit import unpatched libde265 1.0.11-1+deb12u1]

2 years agoImport libde265_1.0.11-1+deb12u1.debian.tar.xz
Thorsten Alteholz [Sun, 26 Nov 2023 12:03:02 +0000 (13:03 +0100)]
Import libde265_1.0.11-1+deb12u1.debian.tar.xz

[dgit import tarball libde265 1.0.11-1+deb12u1 libde265_1.0.11-1+deb12u1.debian.tar.xz]

2 years agoImport libde265_1.0.11.orig.tar.gz
Joachim Bauch [Thu, 2 Feb 2023 15:06:20 +0000 (16:06 +0100)]
Import libde265_1.0.11.orig.tar.gz

[dgit import orig libde265_1.0.11.orig.tar.gz]