Re: Bug#492806: libavformat52: does not handle STR file demuxing (CVE-2008-3162)

2008-07-30 Thread Nico Golde
Hi Michael, * Michael Gilbert <[EMAIL PROTECTED]> [2008-07-30 09:03]: [...] > >> ubuntu just updated their libavformat packages to patch a problem with > >> STR file demuxing [1]. does this problem apply to debian as well? the > >> CVE number is CVE-2008-3162 [2]. > >> > >> [1] http://www.ubuntu

Re: Bug#492806: libavformat52: does not handle STR file demuxing (CVE-2008-3162)

2008-07-30 Thread Reinhard Tartler
found 492806 0.cvs20060823-8 stop "Michael Gilbert" <[EMAIL PROTECTED]> writes: > ok, i appologize, i did a quick scan of bugs in libavformat, and > somehow missed this. No Problem. Better safe than sorry. > there has not been a DSA to fix this problem in stable. is the > libavformat0d package

Re: Bug#492806: libavformat52: does not handle STR file demuxing (CVE-2008-3162)

2008-07-29 Thread Michael Gilbert
>> Package: libavformat52 >> Version: 0.svn20080206-11 >> Severity: grave >> Tags: security >> Justification: user security hole >> >> ubuntu just updated their libavformat packages to patch a problem with >> STR file demuxing [1]. does this problem apply to debian as well? the >> CVE number is C