Control: tags -1 + confirmed On Wed, 2019-09-18 at 14:42 +0200, IOhannes m zmoelnig wrote: > the binary package libmysofa0 is used by VLC (the ubiquitous media > player) and the ffmpeg framework (the ubiquitous media framework), > and consequently has a popcon of 43382. > > The src:libmysofa package has been assigned a number of CVEs and a > cumulative Debian bug #939735. > The issues (NULL-pointer access, out-of-bound reads, invalid reads > and writes) have been promptly fixed by upstream, who have released a > new version (0.8). >
Please go ahead. Sorry for the delay. Regards, Adam