Debian Package Tracker
Register | Log in
Subscribe

aom

Choose email to subscribe with

general
  • source: aom (main)
  • version: 3.6.0-1
  • maintainer: Debian Multimedia Maintainers (archive) (DMD)
  • uploaders: James Cowgill [DMD]
  • arch: all any
  • std-ver: 4.6.1
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • oldstable: 1.0.0-3
  • stable: 1.0.0.errata1-3
  • stable-bpo: 3.6.0-1~bpo11+1
  • testing: 3.6.0-1
  • unstable: 3.6.0-1
versioned links
  • 1.0.0-3: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.0.0.errata1-3: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 3.6.0-1~bpo11+1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 3.6.0-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • aom-tools
  • libaom-dev
  • libaom-doc
  • libaom3
action needed
8 security issues in bullseye high

There are 8 open security issues in bullseye.

4 important issues:
  • CVE-2020-0478: In extend_frame_lowbd of restoration.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-150780418
  • CVE-2021-30473: aom_image.c in libaom in AOMedia before 2021-04-07 frees memory that is not located on the heap.
  • CVE-2021-30474: aom_dsp/grain_table.c in libaom in AOMedia before 2021-03-30 has a use-after-free.
  • CVE-2021-30475: aom_dsp/noise_model.c in libaom in AOMedia before 2021-03-24 has a buffer overflow.
4 issues left for the package maintainer to handle:
  • CVE-2020-36130: (needs triaging) AOM v2.0.1 was discovered to contain a NULL pointer dereference via the component av1/av1_dx_iface.c.
  • CVE-2020-36131: (needs triaging) AOM v2.0.1 was discovered to contain a stack buffer overflow via the component stats/rate_hist.c.
  • CVE-2020-36133: (needs triaging) AOM v2.0.1 was discovered to contain a global buffer overflow via the component av1/encoder/partition_search.h.
  • CVE-2020-36135: (needs triaging) AOM v2.0.1 was discovered to contain a NULL pointer dereference via the component rate_hist.c.

You can find information about how to handle these issues in the security team's documentation.

Created: 2022-07-04 Last update: 2023-02-22 07:06
1 bug tagged patch in the BTS normal
The BTS contains patches fixing 1 bug, consider including or untagging them.
Created: 2023-02-08 Last update: 2023-03-27 09:00
Depends on packages which need a new maintainer normal
The packages that aom depends on which need a new maintainer are:
  • yasm (#1011573)
    • Build-Depends: yasm
Created: 2022-05-25 Last update: 2023-03-27 07:39
lintian reports 4 warnings normal
Lintian reports 4 warnings about this package. You should make the package lintian clean getting rid of them.
Created: 2023-02-12 Last update: 2023-02-12 17:05
debian/patches: 2 patches to forward upstream low

Among the 2 debian patches available in version 3.6.0-1 of the package, we noticed the following issues:

  • 2 patches where the metadata indicates that the patch has not yet been forwarded upstream. You should either forward the patch upstream or update the metadata to document its real status.
Created: 2023-02-26 Last update: 2023-02-26 15:54
Build log checks report 2 warnings low
Build log checks report 2 warnings
Created: 2018-09-20 Last update: 2018-09-20 02:18
Standards version of the package is outdated. wishlist
The package should be updated to follow the last version of Debian Policy (Standards-Version 4.6.2 instead of 4.6.1).
Created: 2022-12-17 Last update: 2023-02-12 02:13
news
[rss feed]
  • [2023-02-22] aom 3.6.0-1 MIGRATED to testing (Debian testing watch)
  • [2023-02-21] Accepted aom 3.6.0-1~bpo11+1 (source) into bullseye-backports (Boyuan Yang)
  • [2023-02-11] Accepted aom 3.6.0-1 (source) into unstable (Boyuan Yang)
  • [2023-02-01] Accepted aom 3.6.0~rc2-1~exp1 (source) into experimental (Boyuan Yang)
  • [2022-09-27] aom 3.5.0-1 MIGRATED to testing (Debian testing watch)
  • [2022-09-26] Accepted aom 3.5.0-1~bpo11+1 (source) into bullseye-backports (Boyuan Yang)
  • [2022-09-23] Accepted aom 3.5.0-1 (source) into unstable (Boyuan Yang)
  • [2022-09-17] aom 3.5.0~rc1-1 MIGRATED to testing (Debian testing watch)
  • [2022-09-14] Accepted aom 3.5.0~rc1-1 (source) into unstable (Boyuan Yang)
  • [2022-06-22] aom 3.4.0-1 MIGRATED to testing (Debian testing watch)
  • [2022-06-22] aom 3.4.0-1 MIGRATED to testing (Debian testing watch)
  • [2022-06-21] Accepted aom 3.4.0-1~bpo11+1 (source) into bullseye-backports (Boyuan Yang)
  • [2022-06-19] Accepted aom 3.4.0-1 (source) into unstable (Boyuan Yang)
  • [2022-06-09] Accepted aom 3.3.0-2~bpo11+1 (source) into bullseye-backports (Boyuan Yang)
  • [2022-06-09] Accepted aom 3.4.0~rc1-1~exp1 (source) into experimental (Boyuan Yang)
  • [2022-05-19] aom 3.3.0-2 MIGRATED to testing (Debian testing watch)
  • [2022-05-16] Accepted aom 3.3.0-2 (source) into unstable (Boyuan Yang)
  • [2022-03-06] Accepted aom 3.3.0-1~bpo11+1 (source) into bullseye-backports (Boyuan Yang)
  • [2022-02-23] aom 3.3.0-1 MIGRATED to testing (Debian testing watch)
  • [2022-02-20] Accepted aom 3.3.0-1 (source) into unstable (Boyuan Yang)
  • [2021-12-10] aom 3.2.0-2 MIGRATED to testing (Debian testing watch)
  • [2021-12-05] Accepted aom 3.2.0-2 (source) into unstable (Boyuan Yang)
  • [2021-11-13] Accepted aom 3.2.0-1~bpo11+1 (source amd64 all) into bullseye-backports, bullseye-backports (Debian FTP Masters) (signed by: Boyuan Yang)
  • [2021-11-04] aom 3.2.0-1 MIGRATED to testing (Debian testing watch)
  • [2021-11-01] Accepted aom 3.2.0-1 (source) into unstable (Boyuan Yang)
  • [2021-10-30] aom 1.0.0.errata1.ds-1 MIGRATED to testing (Debian testing watch)
  • [2021-10-27] Accepted aom 1.0.0.errata1.ds-1 (source) into unstable (Boyuan Yang)
  • [2021-10-26] Accepted aom 3.2.0-1~exp1 (source amd64 all) into experimental, experimental (Debian FTP Masters) (signed by: Boyuan Yang)
  • [2021-10-21] Accepted aom 1.0.0.errata1.avif-1 (source) into unstable (Boyuan Yang)
  • [2020-01-05] aom 1.0.0.errata1-3 MIGRATED to testing (Debian testing watch)
  • 1
  • 2
bugs [bug history graph]
  • all: 1
  • RC: 0
  • I&N: 0
  • M&W: 1
  • F&P: 0
  • patch: 1
links
  • homepage
  • lintian (0, 4)
  • buildd: logs, checks, reproducibility, cross
  • popcon
  • browse source code
  • edit tags
  • other distros
  • security tracker
  • debian patches
  • debci
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 3.6.0-1
  • 1 bug

Debian Package Tracker — Copyright 2013-2018 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing