Alerts This Week
Warning Icon 1 659
Alerts This Week
Warning Icon 1 659

Debian: DSA-2336-1 Moderate: Ffmpeg Remote Execution Threats

debian
Calendar Grey November 7, 2011
Debian Logo
Several weaknesses identified in libav; it's recommended to upgrade to address potential memory leaks and execution risks.
Multiple vulnerabilities were found in the ffmpeg, a multimedia player, server and encoder: CVE-2011-3362

Summary

Multiple vulnerabilities were found in the ffmpeg, a multimedia player,
server and encoder:

CVE-2011-3362

An integer signedness error in decode_residual_block function of
the Chinese AVS video (CAVS) decoder in libavcodec can lead to
denial of service (memory corruption and application crash) or
possible code execution via a crafted CAVS file.

CVE-2011-3973/CVE-2011-3974

Multiple errors in the Chinese AVS video (CAVS) decoder can lead to
denial of service (memory corruption and application crash) via an
invalid bitstream.

CVE-2011-3504

A memory allocation problem in the Matroska format decoder can lead
to code execution via a crafted file.

For the stable distribution (squeeze), this problem has been fixed in
version 4:0.5.5-1.

For the unstable distribution (sid), this problem has been fixed in
version 4:0.7.2-1 of the libav source package.

Security support for ffmpeg has been discontinued for the oldstable
distribution (lenny) before in DSA 2306.
The current ve...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Package: ffmpeg
CVE ID: CVE-2011-3362 CVE-2011-3973 CVE-2011-3974 CVE-2011-3504

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here