CVE-2017-11665 (http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-11665): The ff_amf_get_field_value function in libavformat/rtmppkt.c in FFmpeg 3.3.2 allows remote RTMP servers to cause a denial of service (Segmentation Violation and application crash) via a crafted stream. Reference: https://gist.github.com/singleghost/7d94dda50856e707e1c92d068bbc244e
that gist is a 404
This is the commit where that issue is fixed https://git.ffmpeg.org/gitweb/ffmpeg.git/commit/ffcc82219cef0928bed2d558b19ef6ea35634130 ChrisADR Security Project Padawan
ok, so 3.3.3 has the fix and we can track stabilization in bug #626414
GLSA Vote: No Cleanup handled in bug #630460