Bug#770918: Two CVEs against FLAC

2014-11-27 Thread Fabian Greffrath
Am Mittwoch, den 26.11.2014, 19:58 -0800 schrieb Erik de Castro Lopo: > One more patch to cherry pick: Thank you very much! I hope to be able to prepare updated packages by next week. - Fabian -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of "unsubscrib

Bug#770918: Two CVEs against FLAC

2014-11-26 Thread Erik de Castro Lopo
Erik de Castro Lopo wrote: > Package: flac > Version: 1.3.0-2+b1 > Severity: serious > Tags: security > > From: http://lists.xiph.org/pipermail/flac-dev/2014-November/005226.html > > > Google Security Team member, Michele Spagnuolo, recently found two potential > > problems in the FLAC code base

Bug#770918: Two CVEs against FLAC

2014-11-25 Thread Erik de Castro Lopo
Package: flac Version: 1.3.0-2+b1 Severity: serious Tags: security From: http://lists.xiph.org/pipermail/flac-dev/2014-November/005226.html > Google Security Team member, Michele Spagnuolo, recently found two potential > problems in the FLAC code base. They are : > > > CVE-2014-9028 : Heap