CVE-2017-15186 http://seclists.org/oss-sec/2017/q4/111 FFmpeg trigger double-free when it parsing an craft AVI file to MKV file using ffvhuff decoder. Affected versions: <= 3.3.4 References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2017-15186 http://seclists.org/oss-sec/2017/q4/111 http://people.canonical.com/~ubuntu-security/cve/2017/CVE-2017-15186.html http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-15186 @ Maintainer(s): Please state when you are ready for stabilization.
GLSA Vote: No Cleanup handled in bug #630460