[FFmpeg-cvslog] [ffmpeg-web] branch master updated. 3c41f26 web/security: add CVE-2022-3109 for 4.3.6

ffmpeg-git at ffmpeg.org ffmpeg-git at ffmpeg.org
Fri Apr 21 20:48:49 EEST 2023


The branch, master has been updated
       via  3c41f26302937909d1c7ac5ad67cc99a8bf98573 (commit)
       via  bd4d927abd3949babe2c2a8bc0c6ac24ebe78a30 (commit)
      from  d2a655736357a5602e2ad31d7d728afe30ccaf4f (commit)


- Log -----------------------------------------------------------------
commit 3c41f26302937909d1c7ac5ad67cc99a8bf98573
Author:     Michael Niedermayer <michael at niedermayer.cc>
AuthorDate: Fri Apr 21 19:46:17 2023 +0200
Commit:     Michael Niedermayer <michael at niedermayer.cc>
CommitDate: Fri Apr 21 19:46:17 2023 +0200

    web/security: add CVE-2022-3109 for 4.3.6

diff --git a/src/security b/src/security
index b6e5157..6ce1cbf 100644
--- a/src/security
+++ b/src/security
@@ -160,6 +160,14 @@ CVE-2020-35965, b0a8b40294ea212c1938348ff112ef1b9bf16bb3
 
 <h2>FFmpeg 4.3</h2>
 
+<h3>4.3.6</h3>
+<p>
+Fixes following vulnerabilities:
+</p>
+<pre>
+CVE-2022-3109, 7694a44baaaa4786995590a8ba2b16acd8ef8177 / 656cb0450aeb73b25d7d26980af342b37ac4c568
+</pre>
+
 <h3>4.3.5</h3>
 <p>
 Fixes following vulnerabilities:

commit bd4d927abd3949babe2c2a8bc0c6ac24ebe78a30
Author:     Michael Niedermayer <michael at niedermayer.cc>
AuthorDate: Fri Apr 21 19:45:50 2023 +0200
Commit:     Michael Niedermayer <michael at niedermayer.cc>
CommitDate: Fri Apr 21 19:45:50 2023 +0200

    web/Add FFmpeg 4.2.9

diff --git a/src/download b/src/download
index e20fc60..beae4a9 100644
--- a/src/download
+++ b/src/download
@@ -484,10 +484,10 @@ libpostproc    55.  7.100</pre>
     </div> <!-- col -->
   </div> <!-- row -->
 
-  <h3 id="release_4.2">FFmpeg 4.2.8 "Ada"</h3>
+  <h3 id="release_4.2">FFmpeg 4.2.9 "Ada"</h3>
 
   <p>
-    4.2.8 was released on 2022-10-11. It is the latest stable FFmpeg release
+    4.2.9 was released on 2023-04-21. It is the latest stable FFmpeg release
     from the 4.2 release branch, which was cut from master on 2019-07-21.
   </p>
   <p>It includes the following library versions:
@@ -504,19 +504,19 @@ libpostproc    55.  5.100</pre>
 
   <div class="row">
     <div class="col-md-3">
-      <a class="btn btn-success" href="releases/ffmpeg-4.2.8.tar.xz">Download xz tarball</a>
-      <small><a href="releases/ffmpeg-4.2.8.tar.xz.asc">PGP signature</a></small>
+      <a class="btn btn-success" href="releases/ffmpeg-4.2.9.tar.xz">Download xz tarball</a>
+      <small><a href="releases/ffmpeg-4.2.9.tar.xz.asc">PGP signature</a></small>
     </div> <!-- col -->
     <div class="col-md-3">
-      <a class="btn btn-success" href="releases/ffmpeg-4.2.8.tar.bz2">Download bzip2 tarball</a>
-      <small><a href="releases/ffmpeg-4.2.8.tar.bz2.asc">PGP signature</a></small>
+      <a class="btn btn-success" href="releases/ffmpeg-4.2.9.tar.bz2">Download bzip2 tarball</a>
+      <small><a href="releases/ffmpeg-4.2.9.tar.bz2.asc">PGP signature</a></small>
     </div> <!-- col -->
     <div class="col-md-3">
-      <a class="btn btn-success" href="releases/ffmpeg-4.2.8.tar.gz">Download gzip tarball</a>
-      <small><a href="releases/ffmpeg-4.2.8.tar.gz.asc">PGP signature</a></small>
+      <a class="btn btn-success" href="releases/ffmpeg-4.2.9.tar.gz">Download gzip tarball</a>
+      <small><a href="releases/ffmpeg-4.2.9.tar.gz.asc">PGP signature</a></small>
     </div> <!-- col -->
     <div class="col-md-3 text-right">
-      <small><a href="https://git.ffmpeg.org/gitweb/ffmpeg.git/shortlog/n4.2.8">Changelog</a></small>
+      <small><a href="https://git.ffmpeg.org/gitweb/ffmpeg.git/shortlog/n4.2.9">Changelog</a></small>
       <a class="btn btn-success" href="https://git.ffmpeg.org/gitweb/ffmpeg.git/blob/refs/heads/release/4.2:/RELEASE_NOTES">Release Notes</a>
     </div> <!-- col -->
   </div> <!-- row -->
diff --git a/src/security b/src/security
index 7011b72..b6e5157 100644
--- a/src/security
+++ b/src/security
@@ -265,6 +265,14 @@ CVE-2021-38094, 99f8d32129dd233d4eb2efa44678a0bc44869f23, ticket/8263, duplicate
 <h2>FFmpeg 4.2</h2>
 
 
+<h3>4.2.9</h3>
+<p>
+Fixes following vulnerabilities:
+</p>
+<pre>
+CVE-2022-3109, b2e1ee39f52e285cd630786019cff5d8d12aa1a1 / 656cb0450aeb73b25d7d26980af342b37ac4c568
+</pre>
+
 <h3>4.2.7</h3>
 <p>
 Fixes following vulnerabilities:

-----------------------------------------------------------------------

Summary of changes:
 src/download | 18 +++++++++---------
 src/security | 16 ++++++++++++++++
 2 files changed, 25 insertions(+), 9 deletions(-)


hooks/post-receive
-- 



More information about the ffmpeg-cvslog mailing list