security backports
Bug #537297 reported by
Reinhard Tartler
This bug affects 1 person
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
ffmpeg (Debian) |
Fix Released
|
Unknown
|
|||
ffmpeg (Ubuntu) |
Fix Released
|
Medium
|
Unassigned | ||
Intrepid |
Invalid
|
Undecided
|
Unassigned | ||
Jaunty |
Won't Fix
|
Undecided
|
Unassigned | ||
Karmic |
Won't Fix
|
Undecided
|
Unassigned | ||
Lucid |
Fix Released
|
Medium
|
Unassigned |
Bug Description
Binary package hint: ffmpeg
various versions of the ffmepg package contain security issues that have fixes in the upstream 0.5 release branch
lucid ships 0.5.1 which has all known patches included.
karmic and jaunty ship the 0.5 release. For these packages, this can be solved either by updating to 0.5.1 by or applying the patches from svn://ffmpeg.
intrepid ships an pre 0.5 version of ffmpeg. For this, I've backported some of those patches, which eventually ended up as DSA-2000: http://
visibility: | private → public |
Changed in ffmpeg (Ubuntu): | |
importance: | Undecided → Medium |
status: | New → Confirmed |
Changed in ffmpeg (Ubuntu Lucid): | |
status: | Confirmed → Fix Released |
Changed in ffmpeg (Ubuntu Karmic): | |
status: | New → Confirmed |
Changed in ffmpeg (Ubuntu Jaunty): | |
status: | New → Confirmed |
Changed in ffmpeg (Ubuntu Intrepid): | |
status: | New → Confirmed |
Changed in ffmpeg (Debian): | |
status: | Unknown → Fix Released |
To post a comment you must log in.
debian mentions these CVE references: CVE-2009-4631, CVE-2009-4632, CVE-2009-4633, CVE-2009-4634, CVE-2009-4635, CVE-2009-4636, CVE-2009-4637, CVE-2009-4638, CVE-2009-4640