** CVE added: http://www.cve.mitre.org/cgi-
bin/cvename.cgi?name=2013-2277

** CVE added: http://www.cve.mitre.org/cgi-
bin/cvename.cgi?name=2013-2495

** CVE added: http://www.cve.mitre.org/cgi-
bin/cvename.cgi?name=2013-2496

** CVE added: http://www.cve.mitre.org/cgi-
bin/cvename.cgi?name=2013-0894

-- 
You received this bug notification because you are a member of Desktop
Packages, which is subscribed to libav in Ubuntu.
https://bugs.launchpad.net/bugs/1160734

Title:
  Merge Libav 0.8.6-1 from unstable

Status in “libav” package in Ubuntu:
  In Progress

Bug description:
  The package 0.8.6 from unstable fixes 4 CVEs:

  h264: check for luma and chroma bit depth being equal (CVE-2013-2277)
  iff: validate CMAP palette size (CVE-2013-2495)
  msrledec: convert to bytestream2 API and add proper bounds checking 
(CVE-2013-2496)
  vorbisdec: Error on bark_map_size equal to 0 (CVE-2013-0894)

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/libav/+bug/1160734/+subscriptions

-- 
Mailing list: https://launchpad.net/~desktop-packages
Post to     : desktop-packages@lists.launchpad.net
Unsubscribe : https://launchpad.net/~desktop-packages
More help   : https://help.launchpad.net/ListHelp

Reply via email to