Bug#770918: Two CVEs against FLAC

2014-11-27 Thread Fabian Greffrath
Am Mittwoch, den 26.11.2014, 19:58 -0800 schrieb Erik de Castro Lopo: One more patch to cherry pick: Thank you very much! I hope to be able to prepare updated packages by next week. - Fabian ___ pkg-multimedia-maintainers mailing list

Bug#770918: Two CVEs against FLAC

2014-11-26 Thread Erik de Castro Lopo
Erik de Castro Lopo wrote: Package: flac Version: 1.3.0-2+b1 Severity: serious Tags: security From: http://lists.xiph.org/pipermail/flac-dev/2014-November/005226.html Google Security Team member, Michele Spagnuolo, recently found two potential problems in the FLAC code base. They are

Bug#770918: Two CVEs against FLAC

2014-11-25 Thread Erik de Castro Lopo
Package: flac Version: 1.3.0-2+b1 Severity: serious Tags: security From: http://lists.xiph.org/pipermail/flac-dev/2014-November/005226.html Google Security Team member, Michele Spagnuolo, recently found two potential problems in the FLAC code base. They are : CVE-2014-9028 : Heap