touch-packages team mailing list archive
-
touch-packages team
-
Mailing list archive
-
Message #08573
[Bug 1354755] Re: Libav security fixes Aug 2014
Thanks for the Trusty package, looks good, ACK. Uploading for building
now and will release tomorrow.
Thanks!
** Also affects: libav (Ubuntu Precise)
Importance: Undecided
Status: New
** Changed in: libav (Ubuntu Precise)
Assignee: (unassigned) => Marc Deslauriers (mdeslaur)
** Changed in: libav (Ubuntu Precise)
Status: New => In Progress
** Changed in: libav (Ubuntu Trusty)
Status: New => In Progress
** Changed in: libav (Ubuntu Precise)
Importance: Undecided => High
** Changed in: libav (Ubuntu Trusty)
Assignee: (unassigned) => Marc Deslauriers (mdeslaur)
--
You received this bug notification because you are a member of Ubuntu
Touch seeded packages, which is subscribed to libav in Ubuntu.
https://bugs.launchpad.net/bugs/1354755
Title:
Libav security fixes Aug 2014
Status in “libav” package in Ubuntu:
New
Status in “libav” source package in Precise:
In Progress
Status in “libav” source package in Trusty:
In Progress
Bug description:
Trusty should get version 9.16:
version 9.16:
- vp3: Copy all 3 frames for thread updates (CVE-2011-3934)
- mpegts: Do not try to write a PMT larger than SECTION_SIZE (CVE-2014-2263)
- mpegts: Define the section length with a constant
- error_concealment: avoid using the picture if not fully setup (CVE-2013-0860)
- svq1: do not modify the input packet
- cdgraphics: do not return 0 from the decode function
- cdgraphics: switch to bytestream2 (CVE-2013-3674)
- huffyuvdec: check width size for yuv422p (CVE-2013-0848)
- mmvideo: check horizontal coordinate too (CVE-2013-3672)
- wmalosslessdec: fix mclms_coeffs* array size (CVE-2014-2098)
- lavc: Check the image size before calling get_buffer (CVE-2011-3935)
- huffyuv: Check and propagate function return values (CVE-2013-0868)
- h264: prevent theoretical infinite loop in SEI parsing (CVE-2011-3946)
- h264_sei: check SEI size
- pgssubdec: Check RLE size before copying (CVE-2013-0852)
- fate: Add dependencies for dct/fft/mdct/rdft tests
- video4linux2: Avoid a floating point exception
- vf_select: Drop a debug av_log with an unchecked double to enum conversion
- eamad: use the bytestream2 API instead of AV_RL (CVE-2013-0851)
To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/libav/+bug/1354755/+subscriptions
References