libav 6:11.6-1~deb8u1 source package in Debian

Changelog

libav (6:11.6-1~deb8u1) jessie-security; urgency=medium

  * New upstream release fixing multiple security issues.
    - concat: disable by default (CVE-2016-1897, CVE-2016-1898)
    - aac_parser: add required padding for GetBitContext buffer
    - ac3_parser: add required padding for GetBitContext buffer
    - imc: add required padding for GetBitContext buffer
    - h263: Always check both dimensions
    - opusdec: properly handle mismatching configurations in multichannel
      streams
    - mov: Correctly allocate ctts_data
    - aac: Wait to know the channels before allocating frame
    - rtpdec_asf: Check memory allocation and free memory on error
    - jack: Check memory allocation
    - mov: Check memory allocation
    - mkv: Correctly report the latest packet had been flushed
    - aic: Fix slice size computation for widths multiples of 32 macroblocks
    - webp: Make sure enough bytes are available
    - g726: Do not crash on user mistake
    - bytestream2: set the reader to the end when reading more than available
    - vp7: bound checking in vp7_decode_frame_header
    - mux: Make sure that the data is actually written
    - file: properly forward errors from file_read() and file_write()
    - mmvideo: Make sure the rle does not write over the frame boundaries
    - opus: Buffer the samples from the correct offset
    - nut: Use the correct codec_tag when multiple are available
    - truemotion2: Fix the buffer check
    - mimic: Always return on failure
    - msnwc_tcp: Correctly report failure
    - rpza: Check the blocks left before processing one
    - dvdsubdec: Validate the RLE offsets
    - avi: Validate the stream-id for DV as well
    - mov: Use the correct type for size
  * debian/confflags: Force --disable-protocol=concat.
  * debian/patches/CVE-2016-2326.patch: avformat/asfenc: Check pts.
    (CVE-2016-2326)

 -- Sebastian Ramacher <email address hidden>  Wed, 02 Mar 2016 23:13:43 +0100

Upload details

Uploaded by:
Debian Multimedia Maintainers
Uploaded to:
Jessie
Original maintainer:
Debian Multimedia Maintainers
Architectures:
any all
Section:
libs
Urgency:
Medium Urgency

See full publishing history Publishing

Series Pocket Published Component Section

Builds

Downloads

File Size SHA-256 Checksum
libav_11.6-1~deb8u1.dsc 3.9 KiB 2a4d4afc2decf8b5e18d649d5be55cac58912f860e16b0b38fafa47811b50753
libav_11.6.orig.tar.xz 4.6 MiB 542f30e4266d2d2226e681b888bc718c995f5438f2db66a9a27d581243d27aed
libav_11.6-1~deb8u1.debian.tar.xz 68.6 KiB 85d432d69d3706c994b8d7e2ca5c347874f0aa7f70203df3d5ff3569f5347926

No changes file available.

Binary packages built by this source