Debian Package Tracker
Register | Log in
Subscribe

flvmeta

Metadata injector for FLV video files

Choose email to subscribe with

general
  • source: flvmeta (main)
  • version: 1.2.2-2
  • maintainer: Neutron Soutmun (DMD)
  • arch: any
  • std-ver: 4.7.3
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • o-o-stable: 1.2.1-1
  • oldstable: 1.2.1-1
  • stable: 1.2.2-1
  • testing: 1.2.2-2
  • unstable: 1.2.2-2
versioned links
  • 1.2.1-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.2.2-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.2.2-2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • flvmeta
action needed
2 security issues in bullseye high

There are 2 open security issues in bullseye.

2 important issues:
  • CVE-2026-82820: A vulnerability was found in FLVMeta up to 1.2.2. Affected is the function amf_string_new of the file src/amf.c of the component AMF String Processing. The manipulation of the argument length results in heap-based buffer overflow. The attack can be launched remotely. The exploit has been made public and could be used. The patch is identified as f412a33b9a84c2d1a9dee145a868feddbf64879e. A patch should be applied to remediate this issue. The project maintainer doubts the security impact: "While I acknowledged the bugs and provided fixes, I have yet to see any way to exploit these alleged vulnerabilities."
  • CVE-2026-82821: A vulnerability was determined in FLVMeta up to 1.2.2. Affected by this vulnerability is the function amf_object_get of the file src/amf.c of the component AMF Object Parsing. This manipulation causes null pointer dereference. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. Patch name: 52642f7dfb76ec7334016622dde60b1ae963d79b. To fix this issue, it is recommended to deploy a patch. The project maintainer doubts the security impact: "While I acknowledged the bugs and provided fixes, I have yet to see any way to exploit these alleged vulnerabilities."
Created: 2026-08-31 Last update: 2026-09-01 05:00
Standards version of the package is outdated. wishlist
The package should be updated to follow the last version of Debian Policy (Standards-Version 4.7.4 instead of 4.7.3).
Created: 2026-03-31 Last update: 2026-03-31 15:01
news
[rss feed]
  • [2026-02-24] flvmeta 1.2.2-2 MIGRATED to testing (Debian testing watch)
  • [2026-02-19] Accepted flvmeta 1.2.2-2 (source) into unstable (Neutron Soutmun)
  • [2025-09-21] Accepted flvmeta 1.2.2-2~exp1 (source) into experimental (Neutron Soutmun)
  • [2024-11-19] flvmeta 1.2.2-1 MIGRATED to testing (Debian testing watch)
  • [2024-11-13] Accepted flvmeta 1.2.2-1 (source) into unstable (наб) (signed by: Andreas Tille)
  • [2016-10-07] flvmeta 1.2.1-1 MIGRATED to testing (Debian testing watch)
  • [2016-10-02] Accepted flvmeta 1.2.1-1 (source) into unstable (Neutron Soutmun)
  • [2016-08-16] flvmeta 1.2.0-1 MIGRATED to testing (Debian testing watch)
  • [2016-08-10] Accepted flvmeta 1.2.0-1 (source) into unstable (Neutron Soutmun)
  • [2013-11-25] flvmeta 1.1.2-1 MIGRATED to testing (Debian testing watch)
  • [2013-08-15] Accepted flvmeta 1.1.2-1 (source amd64) (Neutron Soutmun)
  • [2013-05-11] Accepted flvmeta 1.1.1-1 (source amd64) (Neutron Soutmun)
  • [2012-10-26] Accepted flvmeta 1.1.0-1 (source amd64) (Neutron Soutmun) (signed by: Theppitak Karoonboonyanan)
  • [2011-11-24] Accepted flvmeta 1.1~r235-2 (source amd64) (Neutron Soutmun)
  • [2011-11-23] Accepted flvmeta 1.1~r235-1 (source amd64) (Neutron Soutmun) (signed by: Theppitak Karoonboonyanan)
  • [2011-06-25] Accepted flvmeta 1.1~r230-1 (source amd64) (Neutron Soutmun)
  • [2011-04-24] Accepted flvmeta 1.1~r221-1 (source amd64) (Neutron Soutmun)
  • [2011-04-14] flvmeta 1.0.11-1 MIGRATED to testing (Debian testing watch)
  • [2011-04-03] Accepted flvmeta 1.0.11-1 (source amd64) (Neutron Soutmun)
bugs [bug history graph]
  • all: 0
links
  • homepage
  • lintian
  • buildd: logs, reproducibility, cross
  • popcon
  • browse source code
  • other distros
  • security tracker
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 1.2.2-2

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing