Overview

Request 458517 accepted

- Add 0001-aacparse-Make-sure-we-have-enough-data-in-the-codec_data-to-be-able-to-parse-it.patch
Make sure there's enough data to parse before doing an
out of bounds read (bsc#1024014, CVE-2016-10198)
- Add 0001-qtdemux-Fix-out-of-bounds-read-in-tag-parsing-code.patch
Fix and out of bounds read in tag parsing code
(bsc#1024017, CVE-2016-10199)
- Add 0001-qtdemux-Increment-current-stts-index-whenever-we-finished.patch
Increment stts index to prevent an out of bounds read and potential crash
(bsc#1024034, CVE-2017-5840)
- Add 0001-avidemux-Fix-various-out-of-bounds-reads-when-parsing-ncdt.patch
Fix various out of bounds reads when parsing ncdt tags
(bsc#1024030, CVE-2017-5841)
- Add 0001-avidemux-Stop-reading-a-ncdt-sub-tag-if-it-goes-behind-the-surrounding-tag.patch
Stop reading a ncdt sub-tag if it goes behind the surrounding tag
to prevent an out of bounds read (bsc#1024062, CVE-2017-5845)

Request History
Antonio Larrosa's avatar

alarrosa created request

- Add 0001-aacparse-Make-sure-we-have-enough-data-in-the-codec_data-to-be-able-to-parse-it.patch
Make sure there's enough data to parse before doing an
out of bounds read (bsc#1024014, CVE-2016-10198)
- Add 0001-qtdemux-Fix-out-of-bounds-read-in-tag-parsing-code.patch
Fix and out of bounds read in tag parsing code
(bsc#1024017, CVE-2016-10199)
- Add 0001-qtdemux-Increment-current-stts-index-whenever-we-finished.patch
Increment stts index to prevent an out of bounds read and potential crash
(bsc#1024034, CVE-2017-5840)
- Add 0001-avidemux-Fix-various-out-of-bounds-reads-when-parsing-ncdt.patch
Fix various out of bounds reads when parsing ncdt tags
(bsc#1024030, CVE-2017-5841)
- Add 0001-avidemux-Stop-reading-a-ncdt-sub-tag-if-it-goes-behind-the-surrounding-tag.patch
Stop reading a ncdt sub-tag if it goes behind the surrounding tag
to prevent an out of bounds read (bsc#1024062, CVE-2017-5845)


Maintenance Bot's avatar

maintbot added gstreamer-plugins-good as a reviewer

Submission for gstreamer-plugins-good by someone who is not maintainer in the devel project (multimedia:libs). Please review


Maintenance Bot's avatar

maintbot accepted review

accepted


Bjørn Lie's avatar

Zaitor accepted review

ok


Bjørn Lie's avatar

Zaitor approved review

ok


Matthias Gerstner's avatar

mgerstner moved maintenance target to openSUSE:Maintenance:6428


Matthias Gerstner's avatar

mgerstner accepted request

ok

openSUSE Build Service is sponsored by