Debdiff for updating from 2.8.11 to 2.8.14 is attached. The only change other than importing the new upstream version is a change to debian/gbp.conf which should have no impact on the generated binaries (it only affects my git packaging).
Git repo on salsa: https://salsa.debian.org/multimedia- team/ffmpeg/commits/ubuntu/xenial I have: - Checked the list of fixed CVEs. - Verified the package builds in xenial. - Verified the packages install + upgrade from the current version in xenial-security. - Verified the autopkgtests pass. - Run some smoke tests to make sure the basic parts still work. Since this is a massive update, so I have not had time to verify each specific bug. ** Patch added: "ffmpeg_2.8.14-0ubuntu0.16.04.1.debdiff" https://bugs.launchpad.net/ubuntu/+source/ffmpeg/+bug/1697785/+attachment/5109402/+files/ffmpeg_2.8.14-0ubuntu0.16.04.1.debdiff ** Summary changed: - Update to 2.8.13 in Xenial + Update to 2.8.14 in Xenial ** CVE added: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2017-11399 ** CVE added: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2017-11665 ** CVE added: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2017-14055 ** CVE added: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2017-14056 ** CVE added: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2017-14057 ** CVE added: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2017-14058 ** CVE added: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2017-14059 ** CVE added: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2017-14169 ** CVE added: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2017-14170 ** CVE added: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2017-14171 ** CVE added: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2017-14222 ** CVE added: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2017-14223 ** CVE added: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2017-14225 ** CVE added: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2017-15672 ** CVE added: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2017-17081 -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1697785 Title: Update to 2.8.14 in Xenial To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/ffmpeg/+bug/1697785/+subscriptions -- ubuntu-bugs mailing list ubuntu-bugs@lists.ubuntu.com https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs