Alerts This Week
Warning Icon 1 700
Alerts This Week
Warning Icon 1 700

Debian 0.svn20080206-18+lenny3 Critical: FFmpeg Buffer Overflow Exploit

debian
Calendar Grey February 16, 2011
Debian Logo
Ubuntu Security Notice USN-4703-1 deals with significant vulnerabilities in OpenSSL, impacting network services.
Several vulnerabilities have been discovered in FFmpeg coders, which are used by by MPlayer and other applications

Summary

Several vulnerabilities have been discovered in FFmpeg coders, which are used by
by MPlayer and other applications.


CVE-2010-3429

Cesar Bernardini and Felipe Andres Manzano reported an arbitrary offset
dereference vulnerability in the libavcodec, in particular in the flic file
format parser. A specific flic file may exploit this vulnerability and execute
arbitrary code. Mplayer is also affected by this problem, as well as other
software that use this library.


CVE-2010-4704

Greg Maxwell discovered an integer overflow the Vorbis decoder in FFmpeg. A
specific ogg file may exploit this vulnerability and execute arbitrary code.


CVE-2010-4705

A potential integer overflow has been discovered in the Vorbis decoder in
FFmpeg.


This upload also fixes an incomplete patch from DSA-2000-1. Michael Gilbert
noticed that there was remaining vulnerabilities, which may cause a denial of
service and potentially execution of arbitrary code.

For the oldstable distribution (lenny), this problem h...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Package: ffmpeg-debian
CVE ID: CVE-2010-3429 CVE-2010-4704 CVE-2010-4705

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here