FS#36954 - [ffmpeg] security patches for 3 CVEs

Attached to Project: Arch Linux
Opened by RbN (RbN) - Monday, 16 September 2013, 18:48 GMT
Last edited by Bartłomiej Piotrowski (Barthalion) - Tuesday, 17 September 2013, 08:36 GMT
Task Type Bug Report
Category Packages: Extra
Status Closed
Assigned To Bartłomiej Piotrowski (Barthalion)
Architecture All
Severity High
Priority Normal
Reported Version
Due in Version Undecided
Due Date Undecided
Percent Complete 100%
Votes 0
Private No

Details

[ffmpeg] security patches for 3 CVEs
security patches for :
CVE-2013-4263
CVE-2013-4264
CVE-2013-4265

Cve attribution on oss-sec [1]

The patches [2] [3] [4] fix those vulnerabilities.


[1] http://www.openwall.com/lists/oss-security/2013/08/21/1
[2] https://github.com/FFmpeg/FFmpeg/commit/e43a0a232dbf6d3c161823c2e07c52e76227a1bc
[3] https://github.com/FFmpeg/FFmpeg/commit/2960576378d17d71cc8dccc926352ce568b5eec1
[4] https://github.com/FFmpeg/FFmpeg/commit/2960576378d17d71cc8dccc926352ce568b5eec1
This task depends upon

Closed by  Bartłomiej Piotrowski (Barthalion)
Tuesday, 17 September 2013, 08:36 GMT
Reason for closing:  Fixed
Additional comments about closing:  ffmpeg 2.0.1-2
Comment by DrZaius (DrZaius) - Monday, 16 September 2013, 20:11 GMT
You used the same commit hash for [3] and [4]. Isn't [4] supposed to be c94f9e854228e0ea00e1de8769d8d3f7cab84a55?
Comment by RbN (RbN) - Monday, 16 September 2013, 20:37 GMT

Loading...