Re: [FFmpeg-devel] CVE #s security fixes and backports

2025-02-23 Thread Michael Niedermayer
Hi On Sun, Feb 23, 2025 at 07:00:47PM -0300, James Almer wrote: > On 2/23/2025 6:58 PM, Michael Niedermayer wrote: > > Hi > > > > On Sun, Feb 23, 2025 at 06:45:07PM -0300, James Almer wrote: > > > On 2/23/2025 5:19 PM, Michael Niedermayer wrote: > > > > Hi > > > > > > > > On Sun, Feb 23, 2025 at

Re: [FFmpeg-devel] CVE #s security fixes and backports

2025-02-23 Thread James Almer
On 2/23/2025 6:58 PM, Michael Niedermayer wrote: Hi On Sun, Feb 23, 2025 at 06:45:07PM -0300, James Almer wrote: On 2/23/2025 5:19 PM, Michael Niedermayer wrote: Hi On Sun, Feb 23, 2025 at 12:41:23PM -0300, James Almer wrote: On 2/23/2025 6:12 AM, Michael Niedermayer wrote: Hi On Sun, Feb

Re: [FFmpeg-devel] CVE #s security fixes and backports

2025-02-23 Thread James Almer
On 2/23/2025 6:58 PM, Michael Niedermayer wrote: Hi On Sun, Feb 23, 2025 at 06:45:07PM -0300, James Almer wrote: On 2/23/2025 5:19 PM, Michael Niedermayer wrote: Hi On Sun, Feb 23, 2025 at 12:41:23PM -0300, James Almer wrote: On 2/23/2025 6:12 AM, Michael Niedermayer wrote: Hi On Sun, Feb

Re: [FFmpeg-devel] CVE #s security fixes and backports

2025-02-23 Thread Michael Niedermayer
Hi On Sun, Feb 23, 2025 at 06:45:07PM -0300, James Almer wrote: > On 2/23/2025 5:19 PM, Michael Niedermayer wrote: > > Hi > > > > On Sun, Feb 23, 2025 at 12:41:23PM -0300, James Almer wrote: > > > On 2/23/2025 6:12 AM, Michael Niedermayer wrote: > > > > Hi > > > > > > > > On Sun, Feb 23, 2025 at

Re: [FFmpeg-devel] CVE #s security fixes and backports

2025-02-23 Thread James Almer
On 2/23/2025 5:19 PM, Michael Niedermayer wrote: Hi On Sun, Feb 23, 2025 at 12:41:23PM -0300, James Almer wrote: On 2/23/2025 6:12 AM, Michael Niedermayer wrote: Hi On Sun, Feb 23, 2025 at 09:56:35AM +0100, Michael Niedermayer wrote: Hi all Today ffmpeg-security was asked why 5 security fix

Re: [FFmpeg-devel] CVE #s security fixes and backports

2025-02-23 Thread Michael Niedermayer
Hi On Sun, Feb 23, 2025 at 06:49:23PM +0200, Rémi Denis-Courmont wrote: > Le sunnuntaina 23. helmikuuta 2025, 11.12.36 UTC+2 Michael Niedermayer a > écrit > : > > On Sun, Feb 23, 2025 at 09:56:35AM +0100, Michael Niedermayer wrote: > > > I suggest > > > 1. if you fix a security issue or apply a

Re: [FFmpeg-devel] CVE #s security fixes and backports

2025-02-23 Thread Michael Niedermayer
Hi On Sun, Feb 23, 2025 at 12:41:23PM -0300, James Almer wrote: > On 2/23/2025 6:12 AM, Michael Niedermayer wrote: > > Hi > > > > On Sun, Feb 23, 2025 at 09:56:35AM +0100, Michael Niedermayer wrote: > > > Hi all > > > > > > Today ffmpeg-security was asked why 5 security fixes are missing in 6.1

Re: [FFmpeg-devel] CVE #s security fixes and backports

2025-02-23 Thread Rémi Denis-Courmont
Le sunnuntaina 23. helmikuuta 2025, 11.12.36 UTC+2 Michael Niedermayer a écrit : > On Sun, Feb 23, 2025 at 09:56:35AM +0100, Michael Niedermayer wrote: > > I suggest > > 1. if you fix a security issue or apply a security fix, make sure it is > > backported to all supported releases > > 2. if you s

Re: [FFmpeg-devel] CVE #s security fixes and backports

2025-02-23 Thread James Almer
On 2/23/2025 6:12 AM, Michael Niedermayer wrote: Hi On Sun, Feb 23, 2025 at 09:56:35AM +0100, Michael Niedermayer wrote: Hi all Today ffmpeg-security was asked why 5 security fixes are missing in 6.1 and from our security page. These issues where posted publically on trac, and fixed by FFmpeg

Re: [FFmpeg-devel] CVE #s security fixes and backports

2025-02-23 Thread Michael Niedermayer
Hi On Sun, Feb 23, 2025 at 09:56:35AM +0100, Michael Niedermayer wrote: > Hi all > > Today ffmpeg-security was asked why 5 security fixes are missing in 6.1 > and from our security page. > > These issues where posted publically on trac, and fixed by FFmpeg developers. > Then someone seems to hav

[FFmpeg-devel] CVE #s security fixes and backports

2025-02-23 Thread Michael Niedermayer
Hi all Today ffmpeg-security was asked why 5 security fixes are missing in 6.1 and from our security page. These issues where posted publically on trac, and fixed by FFmpeg developers. Then someone seems to have registered CVE #s but not mailed ffmpeg-security I suggest 1. if you fix a security