http://git.videolan.org/?p=ffmpeg.git;a=commit;h=6f5c5051096a842d49b8ae3b10462a6098d4b890 http://git.videolan.org/?p=ffmpeg.git;a=commit;h=f7c0f8355e5d3a2a5749676d32aec6ea437da984 http://git.videolan.org/?p=ffmpeg.git;a=commit;h=03d30d4c2c4d622ffd8b5603e6c41a7ca1151245 http://git.videolan.org/?p=ffmpeg.git;a=commit;h=f6476944e1a70e1639ad45791cf94972e66ae5bb http://git.videolan.org/?p=ffmpeg.git;a=commit;h=d9bef14e41a49b3ea2be407d02f0fe8d4c4a92eb http://git.videolan.org/?p=ffmpeg.git;a=commit;h=71f0a3c4adcf86303ed53696a70bb7398ae63c69 http://git.videolan.org/?p=ffmpeg.git;a=commit;h=7f90eef87ac84c617b102b689eb68e7cb140167b http://git.videolan.org/?p=ffmpeg.git;a=commit;h=c0c24bc9b32419c7883a344c74a6779374a3c16a http://git.videolan.org/?p=ffmpeg.git;a=commit;h=84d26ab6eb07e22ad6ffcd8109ca1d1a0cd57bce
This is fixed in 1.2.9
there's a new bunch of asan fixes in 1.2.10 which should be ok for stable
we'll go with 2.2.x, 1.2 is not maintained anymore
Added to existing GLSA. These commits are included in the latest 2.8.x so this bug will be included in the latest GLSA release.
(In reply to Aaron Bauman from comment #4) > Added to existing GLSA. These commits are included in the latest 2.8.x so > this bug will be included in the latest GLSA release. That was not meant to imply that they were *recently* included. This bug was missed during previous GLSAs.
This issue was resolved and addressed in GLSA 201606-09 at https://security.gentoo.org/glsa/201606-09 by GLSA coordinator Kristian Fiskerstrand (K_F).