Alerts This Week
Warning Icon 1 540
Alerts This Week
Warning Icon 1 540

Debian: DSA-3957-1 Critical: FFmpeg Denial-of-Service and Code Execution

debian
Calendar Grey August 28, 2017
Debian Logo
Multiple security flaws in FFmpeg may result in denial of service and unauthorized code execution risks. Debian users are advised to update their systems.
Several vulnerabilities have been discovered in FFmpeg, a multimedia player, server and encoder

Summary

CVE-2017-9608

Yihan Lian of Qihoo 360 GearTeam discovered a NULL pointer access when
parsing a crafted MOV file.

CVE-2017-9993

Thierry Foucu discovered that it was possible to leak information from
files and symlinks ending in common multimedia extensions, using the
HTTP Live Streaming.

CVE-2017-11399

Liu Bingchang of IIE discovered an integer overflow in the APE decoder
that can be triggered by a crafted APE file.

CVE-2017-11665

JunDong Xie of Ant-financial Light-Year Security Lab discovered that
an attacker able to craft a RTMP stream can crash FFmpeg.

CVE-2017-11719

Liu Bingchang of IIE discovered an out-of-bound access that can be
triggered by a crafted DNxHD file.

For the stable distribution (stretch), these problems have been fixed in
version 7:3.2.7-1~deb9u1.

We recommend that you upgrade your ffmpeg packages.

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: ...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Package: ffmpeg
CVE ID: CVE-2017-9608 CVE-2017-9993 CVE-2017-11399 CVE-2017-11665

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here