← Back to team overview

touch-packages team mailing list archive

[Bug 1341216] Re: Libav security fixes Jul 2014

 

** Also affects: libav (Ubuntu Trusty)
   Importance: Undecided
       Status: New

** Also affects: libav (Ubuntu Utopic)
   Importance: High
     Assignee: Reinhard Tartler (siretart)
       Status: In Progress

** Also affects: libav (Ubuntu Precise)
   Importance: Undecided
       Status: New

** Also affects: libav (Ubuntu Saucy)
   Importance: Undecided
       Status: New

** Changed in: libav (Ubuntu Trusty)
       Status: New => In Progress

** Changed in: libav (Ubuntu Precise)
       Status: New => In Progress

** Changed in: libav (Ubuntu Saucy)
       Status: New => In Progress

** Changed in: libav (Ubuntu Precise)
     Assignee: (unassigned) => Marc Deslauriers (mdeslaur)

** Changed in: libav (Ubuntu Saucy)
     Assignee: (unassigned) => Marc Deslauriers (mdeslaur)

-- 
You received this bug notification because you are a member of Ubuntu
Touch seeded packages, which is subscribed to libav in Ubuntu.
https://bugs.launchpad.net/bugs/1341216

Title:
  Libav security fixes Jul 2014

Status in “libav” package in Ubuntu:
  In Progress
Status in “libav” source package in Precise:
  In Progress
Status in “libav” source package in Saucy:
  In Progress
Status in “libav” source package in Trusty:
  In Progress
Status in “libav” source package in Utopic:
  In Progress

Bug description:
  trusty should get Libav 9.14:

  version 9.14:                                                                                                                                
  - adpcm: Write the proper predictor in trellis mode in IMA QT                                                                                
  - adpcm: Avoid reading out of bounds in the IMA QT trellis encoder                                                                           
  - Check mp3 header before calling avpriv_mpegaudio_decode_header() (bug/705)                                                                 
  - Check if an mp3 header is using a reserved sample rate                                                                                     
  - lzo: Handle integer overflow (bug/704)                                                                                                     
  - avconv: make -shortest work with streamcopy                                                                                                

  The lzo issue is claimed to be exploitable (remote code execution) on
  i386.

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/libav/+bug/1341216/+subscriptions


References