New Debian ffmpeg 7:4.1.11-0+deb10u3 fixes: This update addresses the following issues: 7:4.1.11-0+deb10u3 (Wed, 29 Jan 2025 22:03:02 +0100) * Non-maintainer upload by the ELTS Team. * CVE-2024-36618 Fix integer overflow if ULONG_MAX < INT64_MAX * CVE-2024-36617 don't seek beyond 64bit * CVE-2024-36616 2147483424 * 2 cannot be represented in type 'int' * CVE-2024-35368 Fix double-free on error * CVE-2024-35367 Fix out-of-bounds access * CVE-2024-35366 Check for negative duration
--- mirror/ftp/pool/main/f/ffmpeg/ffmpeg_4.1.11-0+deb10u2.dsc +++ apt/ucs_5.0-0-errata5.0-9/source/ffmpeg_4.1.11-0+deb10u3.dsc @@ -1,3 +1,19 @@ +7:4.1.11-0+deb10u3 [Wed, 29 Jan 2025 22:03:02 +0100] Thorsten Alteholz <debian@alteholz.de>: + + * Non-maintainer upload by the ELTS Team. + * CVE-2024-36618 + Fix integer overflow if ULONG_MAX < INT64_MAX + * CVE-2024-36617 + don't seek beyond 64bit + * CVE-2024-36616 + 2147483424 * 2 cannot be represented in type 'int' + * CVE-2024-35368 + Fix double-free on error + * CVE-2024-35367 + Fix out-of-bounds access + * CVE-2024-35366 + Check for negative duration + 7:4.1.11-0+deb10u2 [Mon, 28 Oct 2024 22:16:34 +0200] Adrian Bunk <bunk@debian.org>: * Non-maintainer upload by the ELTS Team. <http://piuparts.knut.univention.de/5.0-9/#3771552085715740841>
OK: bug OK: yaml OK: announce_errata OK: patch OK: piuparts [5.0-9] c12fee05ec Bug #57939: ffmpeg 7:4.1.11-0+deb10u3 doc/errata/staging/ffmpeg.yaml | 26 ++++++++++++++++++++++++++ 1 file changed, 26 insertions(+)
<https://errata.software-univention.de/#/?erratum=5.0x1208>