[FFmpeg-devel] backport fixes for CVE-2019-9718 and CVE-2019-9721

Carl Eugen Hoyos ceffmpeg at gmail.com
Wed Mar 20 01:48:12 EET 2019


2019-03-19 23:28 GMT+01:00, Dominik 'Rathann' Mierzejewski
<dominik at greysector.net>:

> Were the CVE IDs not known at the time these were pushed to master?

No, how would this be possible?

> Not having them in the commit log made it more difficult to find them.

I thought the CVE's themselves contains the commits, no?

Carl Eugen


More information about the ffmpeg-devel mailing list