Moritz Muehlenhoff
2008-Jul-08 23:08 UTC
[Secure-testing-team] Bug#489965: libavformat52: Buffer overflow in STR demuxer
Package: libavformat52 Version: 0.svn20080206-9 Severity: grave Tags: security Justification: user security hole I noticed the following issue when browsing ffmpeg commit logs: http://svn.mplayerhq.hu/ffmpeg?view=rev&revision=13993 https://roundup.mplayerhq.hu/roundup/ffmpeg/issue311 Cheers, Moritz -- System Information: Debian Release: lenny/sid APT prefers unstable APT policy: (500, ''unstable'') Architecture: i386 (i686) Kernel: Linux 2.6.25-2-686 (SMP w/1 CPU core) Locale: LANG=C, LC_CTYPE=de_DE.ISO-8859-15 at euro (charmap=ISO-8859-15) Shell: /bin/sh linked to /bin/bash Versions of packages libavformat52 depends on: ii libavcodec51 0.svn20080206-9 ffmpeg codec library ii libavutil49 0.svn20080206-9 ffmpeg utility library ii libc6 2.7-12 GNU C Library: Shared libraries ii zlib1g 1:1.2.3.3.dfsg-12 compression library - runtime libavformat52 recommends no packages. -- no debconf information