Bug#641478: libavcodec insufficient boundary check in CAVS decoding

2011-09-13 Thread Reinhard Tartler
On Di, Sep 13, 2011 at 09:43:11 (PDT), Moritz Muehlenhoff wrote: > Package: libav > Severity: important > > The following was reported by oCERT: > http://www.ocert.org/advisories/ocert-2011-002.html > > A CVE ID is not yet available, I will be requesting one. This is unfixed > in libav from sid. T

Bug#641478: libavcodec insufficient boundary check in CAVS decoding

2011-09-13 Thread Moritz Muehlenhoff
Package: libav Severity: important The following was reported by oCERT: http://www.ocert.org/advisories/ocert-2011-002.html A CVE ID is not yet available, I will be requesting one. This is unfixed in libav from sid. The ffmpeg fix can be found here: http://git.videolan.org/?p=ffmpeg.git;a=commit;