-
Committer:
Bazaar Package Importer
-
Author(s):
Martin Pitt
-
Date:
2005-12-15 13:13:45 UTC
-
mfrom:
(0.1.2 upstream)
-
Revision ID:
james.westby@ubuntu.com-20051215131345-8n4osv1j7fy9c1s1
* SECURITY UPDATE: Fix arbitrary code execution with crafted PNG images in
embedded ffmpeg copy.
* src/libffmpeg/libavcodec/utils.c, avcodec_default_get_buffer(): Apply
upstream patch to fix buffer overflow on decoding of small PIX_FMT_PAL8
PNG files.
* References:
CVE-2005-4048
http://mplayerhq.hu/pipermail/ffmpeg-devel/2005-November/005333.html
http://www1.mplayerhq.hu/cgi-bin/cvsweb.cgi/ffmpeg/libavcodec/
utils.c.diff?r1=1.161&r2=1.162&cvsroot=FFMpeg