Marc, I'm assuming this is related to this https://scarybeastsecurity.blogspot.ca/2016/11/0day-exploit-advancing- exploitation.html, right?
Like the author, I question the upstream decision to include FLIC support in the "good" set. Would it be possible to move that plugin to the "bad" or the "ugly" set since it's presumably a very rarely used format? -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to gst-plugins-good0.10 in Ubuntu. https://bugs.launchpad.net/bugs/1643901 Title: flxdec security update tracking bug Status in gst-plugins-good0.10 package in Ubuntu: Invalid Status in gst-plugins-good1.0 package in Ubuntu: Confirmed Status in gst-plugins-good0.10 source package in Precise: In Progress Status in gst-plugins-good1.0 source package in Precise: Invalid Status in gst-plugins-good0.10 source package in Trusty: In Progress Status in gst-plugins-good1.0 source package in Trusty: In Progress Status in gst-plugins-good0.10 source package in Xenial: In Progress Status in gst-plugins-good1.0 source package in Xenial: In Progress Status in gst-plugins-good0.10 source package in Yakkety: Invalid Status in gst-plugins-good1.0 source package in Yakkety: In Progress Status in gst-plugins-good0.10 source package in Zesty: Invalid Status in gst-plugins-good1.0 source package in Zesty: Confirmed Bug description: This bug is to track the security update to fix the flxdec out-of- bounds write. To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/gst-plugins-good0.10/+bug/1643901/+subscriptions -- Mailing list: https://launchpad.net/~touch-packages Post to : touch-packages@lists.launchpad.net Unsubscribe : https://launchpad.net/~touch-packages More help : https://help.launchpad.net/ListHelp