Bug#775593: Bug#773626: libav: multiple security issues

2015-03-14 Thread Sebastian Ramacher
Version: 11.3-1 On 2015-01-17 20:56:02, Sebastian Ramacher wrote: Control: clone -1 -2 Control: retitle -2 libav: CVE-2014-{8544,8546,9316,9318,9319} Control: tags -1 + fixed-upstream pending On 2014-12-20 23:31:11, Michael Gilbert wrote: CVE-2014-8544[4]: | libavcodec/tiff.c in FFmpeg

Bug#775593: Bug#773626: libav: multiple security issues

2015-01-19 Thread Bálint Réczey
2015-01-18 20:41 GMT+01:00 Reinhard Tartler siret...@gmail.com: Control: severity -1 important On Sat, Jan 17, 2015 at 2:56 PM, Sebastian Ramacher sramac...@debian.org wrote: On 2014-12-20 23:31:11, Michael Gilbert wrote: CVE-2014-8544[4]: | libavcodec/tiff.c in FFmpeg before 2.4.2 does not

Bug#775593: Bug#773626: libav: multiple security issues

2015-01-19 Thread Reinhard Tartler
Control: forwarded -1 https://bugzilla.libav.org/show_bug.cgi?id=805 On Mon, Jan 19, 2015 at 8:42 AM, Bálint Réczey bal...@balintreczey.hu wrote: Probably asking FFmpeg upstream would help, maybe Libav upstream also have been notified about the details. Great idea. I've forwarded this bug to

Bug#775593: Bug#773626: libav: multiple security issues

2015-01-19 Thread Bálint Réczey
Hi Reinhard, 2015-01-19 17:13 GMT+01:00 Reinhard Tartler siret...@gmail.com: Control: forwarded -1 https://bugzilla.libav.org/show_bug.cgi?id=805 On Mon, Jan 19, 2015 at 8:42 AM, Bálint Réczey bal...@balintreczey.hu wrote: Probably asking FFmpeg upstream would help, maybe Libav upstream also

Bug#775593: Bug#773626: libav: multiple security issues

2015-01-18 Thread Reinhard Tartler
Control: severity -1 important On Sat, Jan 17, 2015 at 2:56 PM, Sebastian Ramacher sramac...@debian.org wrote: On 2014-12-20 23:31:11, Michael Gilbert wrote: CVE-2014-8544[4]: | libavcodec/tiff.c in FFmpeg before 2.4.2 does not properly validate | bits-per-pixel fields, which allows remote

Bug#773626: libav: multiple security issues

2015-01-17 Thread Sebastian Ramacher
Control: clone -1 -2 Control: retitle -2 libav: CVE-2014-{8544,8546,9316,9318,9319} Control: tags -1 + fixed-upstream pending On 2014-12-20 23:31:11, Michael Gilbert wrote: CVE-2014-8544[4]: | libavcodec/tiff.c in FFmpeg before 2.4.2 does not properly validate | bits-per-pixel fields, which

Bug#773626: libav: multiple security issues

2014-12-20 Thread Michael Gilbert
package: src:libav version: 6:0.8.16-1 severity: serious tags: security Hi, the following vulnerabilities were published for libav. CVE-2014-8541[0]: | libavcodec/mjpegdec.c in FFmpeg before 2.4.2 considers only dimension | differences, and not bits-per-pixel differences, when determining |