Sultan caught this before MITRE's made this public, so all we really have to go on is the commit message: "avformat/mov: Check count sums in build_open_gop_key_points() Fixes: ffmpeg.md Fixes: Out of array access Fixes: CVE-2022-2566"
~ given ffmpeg-5 is hard masked still.
The bug has been referenced in the following commit(s): https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=2982cf6b9e81c0f29b7c05e2daa28c5455bcd3df commit 2982cf6b9e81c0f29b7c05e2daa28c5455bcd3df Author: John Helmert III <ajak@gentoo.org> AuthorDate: 2022-10-10 15:31:44 +0000 Commit: John Helmert III <ajak@gentoo.org> CommitDate: 2022-10-10 15:31:58 +0000 media-video/ffmpeg: drop 5.0.1 Bug: https://bugs.gentoo.org/870022 Signed-off-by: John Helmert III <ajak@gentoo.org> media-video/ffmpeg/Manifest | 2 - media-video/ffmpeg/ffmpeg-5.0.1.ebuild | 606 --------------------------------- 2 files changed, 608 deletions(-)
Tree is clean.