Update status on CVE-2018-6392/ffmpeg
The vulnerable code, the out of array access in the filter_slice function is present at least in the version in unstable (unless something done wrong during triage), and should be present as well in the streth version: https://sources.debian.org/src/ffmpeg/7:3.2.9-1%7Edeb9u1/libavfilter/vf_transpose.c/#L151 Upstream has adressed the out of array access in https://git.ffmpeg.org/gitweb/ffmpeg.git/commit/c6939f65a116b1ffed345d29d8621ee4ffb32235 but that needed a (functional) regression fix some days later with https://git.ffmpeg.org/gitweb/ffmpeg.git/commit/3f621455d62e46745453568d915badd5b1e5bcd5 This still would need an additional reviev.
Loading
Please register or sign in to comment