Zum Inhalt springen.
Sympa Menü

it-securitynotifies - [IT-SecNots] [SECURITY] [DSA 6007-1] ffmpeg security update

it-securitynotifies AT lists.piratenpartei.de

Betreff: Sicherheitsankündigungen

Listenarchiv

[IT-SecNots] [SECURITY] [DSA 6007-1] ffmpeg security update


Chronologisch Thread  
  • From: Moritz Muehlenhoff <jmm AT debian.org>
  • To: debian-security-announce AT lists.debian.org
  • Subject: [IT-SecNots] [SECURITY] [DSA 6007-1] ffmpeg security update
  • Date: Sun, 21 Sep 2025 14:27:49 +0000
  • Authentication-results: lists.piratenpartei.de; dkim=none; dmarc=none; spf=none (lists.piratenpartei.de: domain of "bounce-debian-security-announce=it-securitynotifies=lists.piratenpartei.de AT lists.debian.org" has no SPF policy when checking 2001:41b8:202:deb:216:36ff:fe40:4002) smtp.mailfrom="bounce-debian-security-announce=it-securitynotifies=lists.piratenpartei.de AT lists.debian.org"
  • List-archive: https://lists.debian.org/msgid-search/aNALZWkudDzqh_k1 AT seger.debian.org
  • List-id: <debian-security-announce.lists.debian.org>
  • List-url: <http://lists.debian.org/debian-security-announce/>
  • Old-dkim-signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=debian.org; s=smtpauto.seger; h=Content-Type:MIME-Version:Message-ID:Subject:To:From:Date :Reply-To:Cc:Content-Transfer-Encoding:Content-ID:Content-Description: In-Reply-To:References; bh=e7rciTBwzCg1tJ/nMuz4mwt/dSzHo7LNXCrh005/6gg=; b=Ow cNJ+vAYfQMzLSQU42yyQBlQOCZYBWevZLdp2TEeJi7JpbBadRdZ4EVTVmyaC5EWsS466XRMwzXqbO mRjXNWD2KIsQVajTXYklUbJFt+aW9tT/jiOi1YTKZZhXhY3Tgt6XfcExr9dXV2CJtRGa3/aS9y0ZT igm0XGg7FUyUWIByFocyAtFj2UqCtX/NeXcCgxLYbOu+KUxFS0wdkmJWCG438dxgnXhawvrzDd87g cwqhF0tqZ2ZOhJhhkYSYgCGhVosjA2AGRYKmTd0F8OmzKoOlgk82xzjgH1gMM6eT8je6N6P/3gTZS FLF9Og0OTWdhT6XcA0C7HOJf//1gyuig==;
  • Old-return-path: <jmm AT seger.debian.org>
  • Priority: urgent
  • Resent-date: Sun, 21 Sep 2025 14:28:15 +0000 (UTC)
  • Resent-from: debian-security-announce AT lists.debian.org
  • Resent-message-id: <jhJgoTW9q8C.A.h1jJ._tA0oB@bendel>
  • Resent-sender: debian-security-announce-request AT lists.debian.org

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

- -------------------------------------------------------------------------
Debian Security Advisory DSA-6007-1 security AT debian.org
https://www.debian.org/security/ Moritz Muehlenhoff
September 21, 2025 https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package : ffmpeg
CVE ID : CVE-2025-1594 CVE-2025-7700 CVE-2025-10256

Several vulnerabilities have been discovered in the FFmpeg multimedia
framework, which could result in denial of service or potentially the
execution of arbitrary code if malformed files/streams are processed.

For the stable distribution (trixie), these problems have been fixed in
version 7:7.1.2-0+deb13u1.

We recommend that you upgrade your ffmpeg packages.

For the detailed security status of ffmpeg please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/ffmpeg

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/

Mailing list: debian-security-announce AT lists.debian.org
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEtuYvPRKsOElcDakFEMKTtsN8TjYFAmjQCy0ACgkQEMKTtsN8
TjaezxAAt+bnQvZ1aRuAq7IvOA8yiDjgj+VhJG+wUi6uP2EHPz+oba+mWDqQuHKt
KyKZW0pQi4mDrBmN0115oTjc1RfXqgfL2rUuWyVy/wBND+5vxtwuHEjCC3dKMJmd
vmwo4Qy5WXj1ArBG3MOFt2DF+MovOwMxIyBYCYYLbwv8YQ8jJiEZVovFhZO3z+Si
/B9I2wzRt24yFeYeHBsy7R1UBZCqdwFAQga9djdX2rG8454hcVcfdSm4jdgJZO/d
KNUbbmavVK5JbfPn4U8CgOdDnduJy3rJDE49enrMOPcyu2gGbReBJXmlnLwXoznC
C57URbzOcm/upvl3BR1iVvnv462WyO8ocwiVfChYBtImXhCGhWwaoolCJGbnXSN+
SEDwC68Z51zHqhdP/F8rb0XDtcS5Jg3Kal+t45FEnjM5xKCCz0S4h1Xt7YP94HU4
QQbw1xTygqE272NNVUJhThHyTd1sxizEIhYofHN74XmJA5Chfw0PLJXnN6DNr63h
DMIJM52iHY1xqQxIx/GoMpK9FCmNdkjaNZZMMxoBMIRU5PIPIVckkW/XmXuCvuMk
q46z6Vwj+TZqLNj9CGlQc1LM4VV+AjgGuCby3H/ZYUu3dWuwXoexndWNpiS5X16p
kbTV1oFTXSPipRE0r2r61ZKtDzphy9OitKg8uWjysnBzve6wayI=
=F4UU
-----END PGP SIGNATURE-----



  • [IT-SecNots] [SECURITY] [DSA 6007-1] ffmpeg security update, Moritz Muehlenhoff, 21.09.2025

Archiv bereitgestellt durch MHonArc 2.6.19+.

Seitenanfang