Bug#688847: libav: multiple CVEs in ffmpeg/libav

2013-01-14 Thread Reinhard Tartler
On Tue, Dec 25, 2012 at 11:31 AM, Moritz Mühlenhoff wrote: > On Mon, Oct 15, 2012 at 05:38:37AM -0400, Reinhard Tartler wrote: >> > None of these are merged into 0.5.x, has the code diverged so much? >> >> I arrived only today from my two week trip and will work on backports >> for 0.7-0.5 this we

Bug#688847: libav: multiple CVEs in ffmpeg/libav

2012-12-25 Thread Moritz Mühlenhoff
On Mon, Oct 15, 2012 at 05:38:37AM -0400, Reinhard Tartler wrote: > > None of these are merged into 0.5.x, has the code diverged so much? > > I arrived only today from my two week trip and will work on backports > for 0.7-0.5 this week. Sorry for the delay. Merry christmas Reinhard, did you have

Bug#688847: libav: multiple CVEs in ffmpeg/libav

2012-10-15 Thread Reinhard Tartler
On Mon, Oct 15, 2012 at 3:39 AM, Moritz Muehlenhoff wrote: > On Sun, Oct 14, 2012 at 05:00:54PM -0400, Reinhard Tartler wrote: >> On Wed, Sep 26, 2012 at 4:22 AM, Yves-Alexis Perez wrote: >> > Source: libav >> > Severity: grave >> > Justification: user security hole >> > >> > Hi, >> > >> > it see

Bug#688847: libav: multiple CVEs in ffmpeg/libav

2012-10-15 Thread Moritz Muehlenhoff
On Sun, Oct 14, 2012 at 05:00:54PM -0400, Reinhard Tartler wrote: > On Wed, Sep 26, 2012 at 4:22 AM, Yves-Alexis Perez wrote: > > Source: libav > > Severity: grave > > Justification: user security hole > > > > Hi, > > > > it seems that a huge pile of CVE were allocated for ffmpeg/libav > > short

Bug#688847: libav: multiple CVEs in ffmpeg/libav

2012-10-14 Thread Reinhard Tartler
On Wed, Sep 26, 2012 at 4:22 AM, Yves-Alexis Perez wrote: > Source: libav > Severity: grave > Justification: user security hole > > Hi, > > it seems that a huge pile of CVE were allocated for ffmpeg/libav short status update: Most/all of the CVEs have now been backported upstream. Before release

Bug#688847: libav: multiple CVEs in ffmpeg/libav

2012-09-26 Thread Yves-Alexis Perez
Source: libav Severity: grave Justification: user security hole Hi, it seems that a huge pile of CVE were allocated for ffmpeg/libav and are supposed to be fixed in 0.11: CVE-2012-2772 CVE-2012-2774 CVE-2012-2775 CVE-2012-2776 CVE-2012-2777 CVE-2012-2779 CVE-2012-2782 CVE-2012-2783 CVE-2012-2