Simon McVittie
2009-Jul-26 18:55 UTC
[Secure-testing-team] Bug#538750: avifile: embedded code copy (ffmpeg)
Package: avifile Version: 1:0.7.47.20070718-1.2 Severity: important Tags: security The FTBFS seen in avifile (#526536) is actually a collision between two symbols in its embedded copy of ffmpeg, which appears to have last changed in 2007. As a result, I suspect it may have unfixed security issues, and it certainly violates best practice. Regards, Simon -- System Information: Debian Release: squeeze/sid APT prefers unstable APT policy: (500, ''unstable''), (500, ''testing''), (500, ''stable''), (101, ''experimental'') Architecture: i386 (x86_64) Kernel: Linux 2.6.30-1-amd64 (SMP w/2 CPU cores) Locale: LANG=en_GB.UTF-8, LC_CTYPE=en_GB.UTF-8 (charmap=UTF-8) Shell: /bin/sh linked to /bin/dash -------------- next part -------------- A non-text attachment was scrubbed... Name: not available Type: application/pgp-signature Size: 155 bytes Desc: Digital signature URL: <http://lists.alioth.debian.org/pipermail/secure-testing-team/attachments/20090726/182a90ba/attachment.pgp>