Bug#1004963: CVE-2020-21598 CVE-2020-21600 CVE-2020-21602

2023-01-22 Thread Tobias Frost
Control: tags -1 fixed 1.0.9-1 TL;DR:  bisecting result. They are all fixed in the upstream 1.0.9 release, marking this as such. (I'll ammend d/changelog when I prepare my NMU. I'll keep bug open until the NMU is in the archives.) The poc is no longer triggering with the state in the master

Bug#1004963: CVE-2020-21598 CVE-2020-21600 CVE-2020-21602

2023-01-21 Thread Tobias Frost
Am 21. Januar 2023 18:14:28 UTC schrieb Salvatore Bonaccorso : >Hi Tobi, > >On Sat, Jan 21, 2023 at 06:21:19PM +0100, Tobias Frost wrote: >> On Fri, 04 Feb 2022 13:14:48 +0100 Moritz Muehlenhoff >> wrote: >> > Source: libde265 >> > Version: 1.0.8-1 >> > Severity: grave >> > Tags: security >> >

Bug#1004963: CVE-2020-21598 CVE-2020-21600 CVE-2020-21602

2023-01-21 Thread Salvatore Bonaccorso
Hi Tobi, On Sat, Jan 21, 2023 at 06:21:19PM +0100, Tobias Frost wrote: > On Fri, 04 Feb 2022 13:14:48 +0100 Moritz Muehlenhoff wrote: > > Source: libde265 > > Version: 1.0.8-1 > > Severity: grave > > Tags: security > > X-Debbugs-Cc: Debian Security Team > > > > CVE-2020-21602: > >

Bug#1004963: CVE-2020-21598 CVE-2020-21600 CVE-2020-21602

2023-01-21 Thread Tobias Frost
On Fri, 04 Feb 2022 13:14:48 +0100 Moritz Muehlenhoff wrote: > Source: libde265 > Version: 1.0.8-1 > Severity: grave > Tags: security > X-Debbugs-Cc: Debian Security Team > > CVE-2020-21602: > https://github.com/strukturag/libde265/issues/242 > > CVE-2020-21600: >

Bug#1004963: CVE-2020-21598 CVE-2020-21600 CVE-2020-21602

2022-02-04 Thread Moritz Muehlenhoff
Source: libde265 Version: 1.0.8-1 Severity: grave Tags: security X-Debbugs-Cc: Debian Security Team CVE-2020-21602: https://github.com/strukturag/libde265/issues/242 CVE-2020-21600: https://github.com/strukturag/libde265/issues/243 CVE-2020-21598: