Debian Security Advisory

DSA-2793-1 libav -- several vulnerabilities

Date Reported:
09 Nov 2013
Affected Packages:
libav
Vulnerable:
Yes
Security database references:
In Mitre's CVE dictionary: CVE-2013-0844, CVE-2013-0850, CVE-2013-0853, CVE-2013-0854, CVE-2013-0857, CVE-2013-0858, CVE-2013-0866.
More information:

Several security issues have been corrected in multiple demuxers and decoders of the libav multimedia library. The CVE IDs mentioned above are just a small portion of the security issues fixed in this update. A full list of the changes is available at http://git.libav.org/?p=libav.git;a=blob;f=Changelog;hb=refs/tags/v0.8.9

For the stable distribution (wheezy), these problems have been fixed in version 0.8.9-1.

For the unstable distribution (sid), these problems have been fixed in version 9.10-1.

We recommend that you upgrade your libav packages.