Bug#775593: Bug#773626: libav: multiple security issues

2015-03-14 Thread Sebastian Ramacher
Version: 11.3-1 On 2015-01-17 20:56:02, Sebastian Ramacher wrote: > Control: clone -1 -2 > Control: retitle -2 libav: CVE-2014-{8544,8546,9316,9318,9319} > Control: tags -1 + fixed-upstream pending > > On 2014-12-20 23:31:11, Michael Gilbert wrote: > > CVE-2014-8544[4]: > > | libavcodec/tiff.c in

Bug#775593: Bug#773626: libav: multiple security issues

2015-01-19 Thread Bálint Réczey
Hi Reinhard, 2015-01-19 17:13 GMT+01:00 Reinhard Tartler : > Control: forwarded -1 https://bugzilla.libav.org/show_bug.cgi?id=805 > > On Mon, Jan 19, 2015 at 8:42 AM, Bálint Réczey wrote: >> Probably asking FFmpeg upstream would help, maybe Libav upstream also >> have been notified about the deta

Processed: Re: Bug#775593: Bug#773626: libav: multiple security issues

2015-01-19 Thread Debian Bug Tracking System
Processing control commands: > forwarded -1 https://bugzilla.libav.org/show_bug.cgi?id=805 Bug #775593 [src:libav] libav: CVE-2014-{8544,8546,9316,9318,9319} Set Bug forwarded-to-address to 'https://bugzilla.libav.org/show_bug.cgi?id=805'. -- 775593: http://bugs.debian.org/cgi-bin/bugreport.cgi

Bug#775593: Bug#773626: libav: multiple security issues

2015-01-19 Thread Reinhard Tartler
Control: forwarded -1 https://bugzilla.libav.org/show_bug.cgi?id=805 On Mon, Jan 19, 2015 at 8:42 AM, Bálint Réczey wrote: > Probably asking FFmpeg upstream would help, maybe Libav upstream also > have been notified about the details. Great idea. I've forwarded this bug to libav upstream. Pleas

Bug#775593: Bug#773626: libav: multiple security issues

2015-01-19 Thread Bálint Réczey
2015-01-18 20:41 GMT+01:00 Reinhard Tartler : > Control: severity -1 important > > On Sat, Jan 17, 2015 at 2:56 PM, Sebastian Ramacher > wrote: >> On 2014-12-20 23:31:11, Michael Gilbert wrote: >>> CVE-2014-8544[4]: >>> | libavcodec/tiff.c in FFmpeg before 2.4.2 does not properly validate >>> | bi

Bug#775593: Bug#773626: libav: multiple security issues

2015-01-18 Thread Reinhard Tartler
Control: severity -1 important On Sat, Jan 17, 2015 at 2:56 PM, Sebastian Ramacher wrote: > On 2014-12-20 23:31:11, Michael Gilbert wrote: >> CVE-2014-8544[4]: >> | libavcodec/tiff.c in FFmpeg before 2.4.2 does not properly validate >> | bits-per-pixel fields, which allows remote attackers to cau