summary |
shortlog | log |
commit |
commitdiff |
tree
first ⋅ prev ⋅ next
Hugo Lefeuvre [Mon, 16 Oct 2017 15:22:05 +0000 (16:22 +0100)]
libav (6:0.8.21-0+deb7u1) wheezy-security; urgency=high
* Non-maintainer upload by the LTS Team.
* New upstream release fixing multiple security issues.
- CVE-2017-7208: buffer over-read in the decode_residual function
in libavcodec.
- CVE-2017-7862: out-of-bounds write caused by a heap-based buffer
overflow related to the decode_frame function in
libavcodec/pictordec.c.
- CVE-2017-9992: Heap-based buffer overflow in the decode_dds1
function in libavcodec/dfa.c.
- CVE-2015-8365: out-of-bounds array access in the smka_decode_frame
function in libavcodec/smacker.c.
[dgit import unpatched libav 6:0.8.21-0+deb7u1]
Hugo Lefeuvre [Mon, 16 Oct 2017 15:22:05 +0000 (16:22 +0100)]
Import libav_0.8.21.orig.tar.xz
[dgit import orig libav_0.8.21.orig.tar.xz]
Hugo Lefeuvre [Mon, 16 Oct 2017 15:22:05 +0000 (16:22 +0100)]
Import libav_0.8.21-0+deb7u1.debian.tar.gz
[dgit import tarball libav 6:0.8.21-0+deb7u1 libav_0.8.21-0+deb7u1.debian.tar.gz]