Summary: | <media-video/ffmpeg-1.0.7: Multiple Vulnerabilities | ||
---|---|---|---|
Product: | Gentoo Security | Reporter: | Agostino Sarubbo <ago> |
Component: | Vulnerabilities | Assignee: | Gentoo Security <security> |
Status: | RESOLVED FIXED | ||
Severity: | normal | CC: | media-video |
Priority: | Normal | ||
Version: | unspecified | ||
Hardware: | All | ||
OS: | Linux | ||
URL: | https://secunia.com/advisories/54044/ | ||
Whiteboard: | A3 [glsa] | ||
Package list: | Runtime testing required: | --- |
Description
Agostino Sarubbo
![]() Not clear which branches this affects, will see when upstream pushes to the release branches. please check the git log of the relevant files. it is likely it is just libav people catching up, that it was fixed long ago in ffmpeg, and this appears in ffmpeg.git history because of the merges. All jpeg2k are backports if they are coming from Michael Niedermayer (as you could guess), the rest should not. (In reply to Luca Barbato from comment #3) > All jpeg2k are backports if they are coming from Michael Niedermayer (as you > could guess), the rest should not. not sure if jpeg2k stuff affects 1.0 branch (it has the old jpeg j2k*.c code) not sure about the others either, these two look similar: http://git.videolan.org/?p=ffmpeg.git;a=commit;h=38229362529ed1619d8ebcc81ecde85b23b45895 http://git.videolan.org/?p=ffmpeg.git;a=commit;h=b21ba20cc83c80fe56192fee3626a8087f37d806 didnt check the rest It looks like the ones that may have affected us, only affected the 0.10 branch and not 1.0. Adding to existing GLSA draft. This issue was resolved and addressed in GLSA 201310-12 at http://security.gentoo.org/glsa/glsa-201310-12.xml by GLSA coordinator Sean Amoss (ackle). |