Bug#871931: libvpx: CVE-2017-0641

2017-08-12 Thread Moritz Mühlenhoff
On Sat, Aug 12, 2017 at 09:37:12PM +0200, Salvatore Bonaccorso wrote: > Hi > > On Sat, Aug 12, 2017 at 01:52:43PM -0400, Ondrej Novy wrote: > > Hi, > > > > we are already using: > > > > --size-limit=16384x16384 > > Yupp, I know that, I added that comment to the tracker. It's not clear > to me

Bug#871931: libvpx: CVE-2017-0641

2017-08-12 Thread Salvatore Bonaccorso
Hi On Sat, Aug 12, 2017 at 01:52:43PM -0400, Ondrej Novy wrote: > Hi, > > we are already using: > > --size-limit=16384x16384 Yupp, I know that, I added that comment to the tracker. It's not clear to me if we need to limit it quite further. The android approach is to limit it to 4k frames. Mabe

Bug#871931: libvpx: CVE-2017-0641

2017-08-12 Thread Ondrej Novy
Hi, we are already using: --size-limit=16384x16384 configure option. So I __think__ we are not vulnerable. -- Best regards Ondřej Nový Email: n...@ondrej.org PGP: 3D98 3C52 EB85 980C 46A5 6090 3573 1255 9D1E 064B

Bug#871931: libvpx: CVE-2017-0641

2017-08-12 Thread Salvatore Bonaccorso
Source: libvpx Version: 1.6.1-3 Severity: important Tags: security upstream Hi, the following vulnerability was published for libvpx. CVE-2017-0641[0]: | A remote denial of service vulnerability in libvpx in Mediaserver | could enable an attacker to use a specially crafted file to cause a |