lp:debian/squeeze/ffmpeg bug 1 Development 2013-02-16 10:16:46 UTC 2013-02-16
* New upstream release. New release f...

Author: Reinhard Tartler
Revision Date: 2013-02-16 10:16:46 UTC

* New upstream release. New release fixes: (Closes: #688849)
  - mpeg12: do not decode extradata more than once (CVE-2012-2803)
  - vp6: properly fail on unsupported feature (CVE-2012-2783)
  - vp56: release frames on error (CVE-2012-2783)
  - shorten: Use separate pointers for the allocated memory for decoded samples (CVE-2012-0858)
  - cavsdec: check for changing w/h (CVE-2012-2777 and CVE-2012-2784)
  - avidec: use actually read size instead of requested size CVE-2012-2788
  - avsdec: Set dimensions instead of relying on the demuxer (CVE-2012-2801)

