Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 507
Alerts This Week
Warning Icon 1 507

Debian FFmpeg Critical Remote Code Exec Risks DSA-2471-1 CVE-2011-3892

debian
Calendar Grey May 13, 2012
Scroller Debian
Debian DSA-2471-1 addresses multiple critical risks in FFmpeg that could allow arbitrary code execution. Immediate updates are critical.
Several vulnerabilities have been discovered in FFmpeg, a multimedia player, server and encoder

Summary

Several vulnerabilities have been discovered in FFmpeg, a multimedia
player, server and encoder. Multiple input validations in the decoders/
demuxers for Westwood Studios VQA, Apple MJPEG-B, Theora, Matroska,
Vorbis, Sony ATRAC3, DV, NSV, files could lead to the execution of
arbitrary code.

These issues were discovered by Aki Helin, Mateusz Jurczyk, Gynvael
Coldwind, and Michael Niedermayer.

For the stable distribution (squeeze), this problem has been fixed in
version 4:0.5.8-1.

For the unstable distribution (sid), this problem has been fixed in
version 6:0.8.2-1 of libav.

We recommend that you upgrade your ffmpeg packages.

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: http://www.debian.org/security/



Severity
critical
Lowest
Low
Medium
High
Critical

Package: ffmpeg
CVE ID: CVE-2011-3892 CVE-2011-3893 CVE-2011-3895 CVE-2011-3929

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.