summaryrefslogtreecommitdiffstats
path: root/documentation/dev-manual/python-development-shell.rst
diff options
context:
space:
mode:
authorDaniel Díaz <daniel.diaz@sonos.com>2025-07-23 17:34:35 -0600
committerSteve Sakoman <steve@sakoman.com>2025-07-30 07:47:48 -0700
commit875170d8f8e33fd19abd6f492d6449a608a6aea4 (patch)
tree8f26c97861b812612f32b795d78c9db94434d7be /documentation/dev-manual/python-development-shell.rst
parent87e1bc09cabe609981d5ee7ea4919755e2072ad9 (diff)
downloadpoky-875170d8f8e33fd19abd6f492d6449a608a6aea4.tar.gz
ffmpeg: Ignore two CVEs fixed in 5.0.3
These two CVEs were fixed via the 5.0.3 release, and the backported patches that fixed them were subsequently left behind (although not deleted) by dadb16481810 ("ffmpeg: upgrade 5.0.1 -> 5.0.3") * CVE-2022-3109: An issue was discovered in the FFmpeg package, where vp3_decode_frame in libavcodec/vp3.c lacks check of the return value of av_malloc() and will cause a null pointer dereference, impacting availability. * CVE-2022-3341: A null pointer dereference issue was discovered in 'FFmpeg' in decode_main_header() function of libavformat/nutdec.c file. The flaw occurs because the function lacks check of the return value of avformat_new_stream() and triggers the null pointer dereference error, causing an application to crash. `bitbake ffmpeg` reports these two as "Unpatched". Ignore them for now, until the NVD updates the versions where these do not affect anymore. (From OE-Core rev: 78aef4b1002c515aa2c1a64fea5bb013c9bc86a8) Signed-off-by: Daniel Díaz <daniel.diaz@sonos.com> Signed-off-by: Steve Sakoman <steve@sakoman.com>
Diffstat (limited to 'documentation/dev-manual/python-development-shell.rst')
0 files changed, 0 insertions, 0 deletions