Openwall Project   /home  Owl  JtR  Pro  crypt  pam_passwdqc  tcb  phpass  scanlogd  popa3d  msulogin  /  Linux  BIND  /  advisories  presentations  /  services  donations  /  wordlists  passwords  /  news  community  lists  wiki  CVSweb  mirrors  signatures
bringing security into open environments
 
Password Recovery Resources on the Net
[<prev] [next>] [month] [year] [list]
Date: Wed, 29 Oct 2008 09:16:59 -0600
From: Vincent Danen <vdanen@...sec.ca>
To: oss-security@...ts.openwall.com
Subject: Fwd: [Full-disclosure] [PLSA 2008-36] Ffmpeg: Multiple
	vulnerabilities

Was looking at the latest ffmpeg issue (CVE-2008-3230) to see if there
were any patches and found this in my inbox as not dealt with yet.
There are no CVE identifiers for any of these issues that I can see.
I'm not sure how many of these issues would be considered security
sensitive/exploitable, but Pardus had issued an advisory and the
references contain the patches to fix them, but even searching on
MITRE's web site shows no ffmpeg CVEs that I've missed.

Do these need CVE identifiers?

-- 
Vincent Danen @ http://linsec.ca/

[ CONTENT OF TYPE message/rfc822 SKIPPED ]

[ CONTENT OF TYPE application/pgp-signature SKIPPED ]

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Hosted by DataForce ISP - Powered by Openwall GNU/*/Linux