Bug#872517: ffmpeg: CVE-2017-7206: heap-based buffer over-read in embed libav

2017-08-18 Thread James Cowgill
Hi, On 18/08/17 03:46, Luciano Bello wrote: > Package: ffmpeg > X-Debbugs-CC: t...@security.debian.org secure-testing- > t...@lists.alioth.debian.org > Severity: grave > Tags: security > > Hi, > > the following vulnerability was published for libav (which is embed in > ffmpeg). > >

Bug#872517: ffmpeg: CVE-2017-7206: heap-based buffer over-read in embed libav

2017-08-18 Thread Carl Eugen Hoyos
Hi! > the following vulnerability was published for libav > (which is embed in ffmpeg). This is not true. Please provide valgrind or asan output (both show the issue easily for some avconv releases) for any affected FFmpeg version or close this issue. Carl Eugen

Bug#872517: ffmpeg: CVE-2017-7206: heap-based buffer over-read in embed libav

2017-08-17 Thread Luciano Bello
Package: ffmpeg X-Debbugs-CC: t...@security.debian.org secure-testing- t...@lists.alioth.debian.org Severity: grave Tags: security Hi, the following vulnerability was published for libav (which is embed in ffmpeg). CVE-2017-7206[0]: | The ff_h2645_extract_rbsp function in libavcodec in libav