~ubuntu-security/ubuntu-cve-tracker/master

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
PublicDateAtUSN: 2011-11-25
Candidate: CVE-2011-4351
PublicDate: 2013-12-09
References: 
 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4351
 http://www.securityfocus.com/archive/1/520621
 http://www.ubuntu.com/usn/usn-1320-1
 http://www.ubuntu.com/usn/usn-1333-1
Description:
 Buffer overflow in FFmpeg before 0.5.6, 0.6.x before 0.6.4, 0.7.x before
 0.7.8, and 0.8.x before 0.8.8 allows remote attackers to execute arbitrary
 code via unspecified vectors.
Ubuntu-Description: 
Notes: 
 mdeslaur> ffmpeg-extra in multiverse needs to have matching version
 mdeslaur> libav-extra is built with tarball produced by libav package
 mdeslaur> This fixes NGS00144
 mdeslaur> As of 2011-12-22, libav is missing the last two commits, but
 mdeslaur> upstream says they aren't necessary.
Bugs: 
Priority: medium
Discovered-by: Phillip Langlois
Assigned-to: mdeslaur
 
Patches_ffmpeg:
 upstream: http://git.videolan.org/?p=ffmpeg.git;a=commitdiff;h=491eaf35ae1f9b619441314bec33766e31580184
 upstream: http://git.videolan.org/?p=ffmpeg.git;a=commitdiff;h=291d74a46d32183653db07818c7b3407fd50a288
 upstream: http://git.videolan.org/?p=ffmpeg.git;a=commitdiff;h=7d49f79f1cd47783a963a757a6563b9cac29db62
 upstream: http://git.videolan.org/?p=ffmpeg.git;a=commitdiff;h=14db3af4f26dad8e6ddf2147e96ccc710952ad4d
 upstream: http://git.videolan.org/?p=ffmpeg.git;a=commitdiff;h=895d258e9ba065d035dd30dbc622423031f0185c
upstream_ffmpeg: needs-triage
hardy_ffmpeg: ignored (reached end-of-life)
lucid_ffmpeg: released (4:0.5.1-1ubuntu1.3)
maverick_ffmpeg: released (4:0.6-2ubuntu6.3)
natty_ffmpeg: DNE
oneiric_ffmpeg: DNE
devel_ffmpeg: DNE

Patches_ffmpeg-extra:
upstream_ffmpeg-extra: needs-triage
hardy_ffmpeg-extra: DNE
lucid_ffmpeg-extra: released (4:0.5.1-1ubuntu1.3)
maverick_ffmpeg-extra: released (4:0.6-2ubuntu3.3)
natty_ffmpeg-extra: DNE
oneiric_ffmpeg-extra: DNE
devel_ffmpeg-extra: DNE

Patches_libav:
 upstream: http://git.libav.org/?p=libav.git;a=commit;h=5a19acb17ceb71657b0eec51dac651953520e5c8
 upstream: http://git.libav.org/?p=libav.git;a=commit;h=291d74a46d32183653db07818c7b3407fd50a288
 upstream: http://git.libav.org/?p=libav.git;a=commit;h=7d49f79f1cd47783a963a757a6563b9cac29db62
upstream_libav: released (0.7.3)
hardy_libav: DNE
lucid_libav: DNE
maverick_libav: DNE
natty_libav: released (4:0.6.4-0ubuntu0.11.04.1)
oneiric_libav: released (4:0.7.3-0ubuntu0.11.10.1)
devel_libav: not-affected (4:0.7.3-2ubuntu1)

Patches_libav-extra:
upstream_libav-extra: needs-triage
hardy_libav-extra: DNE
lucid_libav-extra: DNE
maverick_libav-extra: DNE
natty_libav-extra: released (4:0.6.4-1ubuntu1)
oneiric_libav-extra: released (4:0.7.3ubuntu0.11.10.1)
devel_libav-extra: not-affected (4:0.7.3ubuntu1)