Author: sf Date: 2009-09-30 20:57:03 +0000 (Wed, 30 Sep 2009) New Revision: 12910 Modified: data/CVE/list Log: ffmpeg-debian was renamed back to ffmepg recently Modified: data/CVE/list ==================================================================--- data/CVE/list 2009-09-30 18:47:34 UTC (rev 12909) +++ data/CVE/list 2009-09-30 20:57:03 UTC (rev 12910) @@ -10625,7 +10625,7 @@ CVE-2009-0385 (Integer signedness error in the fourxm_read_header function in ...) {DSA-1782-1 DSA-1781-1} - ffmpeg-debian 0.svn20080206-16 (medium; bug #524799) - - ffmpeg <removed> + - ffmpeg 0.svn20080206-16 - mplayer 1.0~rc2-14 (medium; bug #524805) NOTE: MPlayer links against libavformat since 1.0~rc2-14, etch Mplayer still needs a fix NOTE: http://git.ffmpeg.org/?p=ffmpeg;a=commitdiff;h=72e715fb798f2cb79fd24a6d2eaeafb7c6eeda17 @@ -14724,7 +14724,7 @@ NOTE: only the aac issue affected mplayer because it built against a copy of faad NOTE: the ogm issue is a problem in ffmpeg - ffmpeg-debian <unfixed> (unimportant; bug #509616) - - ffmpeg <removed> (unimportant) + - ffmpeg <unfixed> (unimportant) NOTE: just a crasher, no security implications known so far NOTE: http://sam.zoy.org/blog/2007-01-16-exposing-file-parsing-vulnerabilities CVE-2008-4609 (The TCP implementation in (1) Linux, (2) platforms based on BSD Unix, ...) @@ -18153,7 +18153,7 @@ NOTE: Only a NULL pointer deference, hardly security relevant CVE-2008-3230 (The ffmpeg lavf demuxer allows user-assisted attackers to cause a ...) - ffmpeg-debian 0.svn20080206-16 (unimportant; bug #498764; bug #498766) - - ffmpeg <removed> (unimportant) + - ffmpeg 0.svn20080206-16 (unimportant) NOTE: Only a NULL pointer deference, hardly security relevant CVE-2008-3228 (Joomla! before 1.5.4 does not configure .htaccess to apply certain ...) NOT-FOR-US: Joomla @@ -18319,7 +18319,7 @@ CVE-2008-3162 (Stack-based buffer overflow in the str_read_packet function in ...) {DSA-1781-1} - ffmpeg-debian 0.svn20080206-10 (bug #489965; low) - - ffmpeg <removed> + - ffmpeg 0.svn20080206-10 TODO: Check the various embedders in Etch, horray for librification in Lenny CVE-2008-3161 (Multiple cross-site scripting (XSS) vulnerabilities in ...) NOT-FOR-US: IBM Maximo