Processed: Re: Bug#773626: libav: multiple security issues

2015-01-18 Thread Debian Bug Tracking System
Processing control commands: > severity -1 important Bug #775593 [src:libav] libav: CVE-2014-{8544,8546,9316,9318,9319} Severity set to 'important' from 'serious' -- 775593: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=775593 Debian Bug Tracking System Contact ow...@bugs.debian.org with prob

Bug#775593: Bug#773626: libav: multiple security issues

2015-01-18 Thread Reinhard Tartler
Control: severity -1 important On Sat, Jan 17, 2015 at 2:56 PM, Sebastian Ramacher wrote: > On 2014-12-20 23:31:11, Michael Gilbert wrote: >> CVE-2014-8544[4]: >> | libavcodec/tiff.c in FFmpeg before 2.4.2 does not properly validate >> | bits-per-pixel fields, which allows remote attackers to cau

Processed: Re: Bug#773626: libav: multiple security issues

2015-01-17 Thread Debian Bug Tracking System
Processing control commands: > clone -1 -2 Bug #773626 [src:libav] libav: multiple security issues Bug 773626 cloned as bug 775593 > retitle -2 libav: CVE-2014-{8544,8546,9316,9318,9319} Bug #775593 [src:libav] libav: multiple security issues Changed Bug title to 'libav: CVE-2014-{8544,8546,9316,9

Bug#773626: libav: multiple security issues

2015-01-17 Thread Sebastian Ramacher
Control: clone -1 -2 Control: retitle -2 libav: CVE-2014-{8544,8546,9316,9318,9319} Control: tags -1 + fixed-upstream pending On 2014-12-20 23:31:11, Michael Gilbert wrote: > CVE-2014-8544[4]: > | libavcodec/tiff.c in FFmpeg before 2.4.2 does not properly validate > | bits-per-pixel fields, which

Bug#773626: libav: multiple security issues

2014-12-20 Thread Michael Gilbert
package: src:libav version: 6:0.8.16-1 severity: serious tags: security Hi, the following vulnerabilities were published for libav. CVE-2014-8541[0]: | libavcodec/mjpegdec.c in FFmpeg before 2.4.2 considers only dimension | differences, and not bits-per-pixel differences, when determining | whet