New Debian ffmpeg 7:4.1.11-0+deb10u2 fixes: This update addresses the following issues: 7:4.1.11-0+deb10u2 (Mon, 28 Oct 2024 22:16:34 +0200) * Non-maintainer upload by the ELTS Team. * CVE-2020-20898: avfilter/vf_convolution integer overflow * CVE-2020-22040: avfilter/f_reverse memory leaks * CVE-2020-22051: avfilter/vf_tile memory leak * CVE-2020-22056: avfilter/af_acrossover memory leak * CVE-2021-38090: avfilter/vf_convolution integer overflow * CVE-2021-38091: avfilter/vf_convolution integer overflow * CVE-2021-38092: avfilter/vf_convolution integer overflow * CVE-2021-38093: avfilter/vf_convolution integer overflow * CVE-2021-38094: avfilter/vf_convolution integer overflow * CVE-2022-48434: lavc/pthread_frame hwaccel use-after-free * CVE-2023-49502: avfilter/bwdif buffer overflow * CVE-2023-50010: avfilter/vf_gradfun buffer overflow * CVE-2023-51793: avfilter/vf_weave buffer overflow * CVE-2023-51794: avfilter/af_stereowiden buffer overflow * CVE-2023-51798: avfilter/vf_minterpolate floating point exception * CVE-2024-31578: avutil/hwcontext use-after-free * CVE-2024-32230: avcodec/mpegvideo_enc buffer overflow
*** Bug 57717 has been marked as a duplicate of this bug. ***
--- mirror/ftp/pool/main/f/ffmpeg/ffmpeg_4.1.11-0+deb10u1.dsc +++ apt/ucs_5.0-0-errata5.0-9/source/ffmpeg_4.1.11-0+deb10u2.dsc @@ -1,3 +1,24 @@ +7:4.1.11-0+deb10u2 [Mon, 28 Oct 2024 22:16:34 +0200] Adrian Bunk <bunk@debian.org>: + + * Non-maintainer upload by the ELTS Team. + * CVE-2020-20898: avfilter/vf_convolution integer overflow + * CVE-2020-22040: avfilter/f_reverse memory leaks + * CVE-2020-22051: avfilter/vf_tile memory leak + * CVE-2020-22056: avfilter/af_acrossover memory leak + * CVE-2021-38090: avfilter/vf_convolution integer overflow + * CVE-2021-38091: avfilter/vf_convolution integer overflow + * CVE-2021-38092: avfilter/vf_convolution integer overflow + * CVE-2021-38093: avfilter/vf_convolution integer overflow + * CVE-2021-38094: avfilter/vf_convolution integer overflow + * CVE-2022-48434: lavc/pthread_frame hwaccel use-after-free + * CVE-2023-49502: avfilter/bwdif buffer overflow + * CVE-2023-50010: avfilter/vf_gradfun buffer overflow + * CVE-2023-51793: avfilter/vf_weave buffer overflow + * CVE-2023-51794: avfilter/af_stereowiden buffer overflow + * CVE-2023-51798: avfilter/vf_minterpolate floating point exception + * CVE-2024-31578: avutil/hwcontext use-after-free + * CVE-2024-32230: avcodec/mpegvideo_enc buffer overflow + 7:4.1.11-0+deb10u1 [Tue, 13 Jun 2023 10:16:38 +0200] Sylvain Beucler <beuc@debian.org>: * Non-maintainer upload by the LTS Security Team. <http://piuparts.knut.univention.de/5.0-9/#6410630230805900252>
OK: bug OK: yaml OK: announce_errata OK: patch ~OK: piuparts Freexian ships dbgsym packages [5.0-9] 282bc59f8e Revert "Bug #57715: ffmpeg 7:4.1.11-0+deb10u2" doc/errata/staging/ffmpeg.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) [5.0-9] a9beca3b78 Bug #57715: ffmpeg 7:4.1.11-0+deb10u2 doc/errata/staging/ffmpeg.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) [5.0-9] 159291ec66 Bug #57715: ffmpeg 7:4.1.11-0+deb10u2 doc/errata/staging/ffmpeg.yaml | 40 ++++++++++++++++++++++++++++++++++++++++ 1 file changed, 40 insertions(+)
<https://errata.software-univention.de/#/?erratum=5.0x1155>