-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

- -------------------------------------------------------------------------
Debian Security Advisory DSA-4990-1                   security@debian.org
https://www.debian.org/security/                       Moritz Muehlenhoff
October 19, 2021                      https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package        : ffmpeg
CVE ID         : CVE-2020-20445 CVE-2020-20446 CVE-2020-20453 CVE-2020-21041 
                 CVE-2020-22015 CVE-2020-22016 CVE-2020-22017 CVE-2020-22019 
                 CVE-2020-22020 CVE-2020-22021 CVE-2020-22022 CVE-2020-22023 
                 CVE-2020-22025 CVE-2020-22026 CVE-2020-22027 CVE-2020-22028 
                 CVE-2020-22029 CVE-2020-22030 CVE-2020-22031 CVE-2020-22032 
                 CVE-2020-22033 CVE-2020-22034 CVE-2020-22035 CVE-2020-22036 
                 CVE-2020-22037 CVE-2020-22049 CVE-2020-22054 CVE-2020-35965 
                 CVE-2021-38114 CVE-2021-38171 CVE-2021-38291

Several vulnerabilities have been discovered in the FFmpeg multimedia
framework, which could result in denial of service or potentially the
execution of arbitrary code if malformed files/streams are processed.

For the oldstable distribution (buster), these problems have been fixed
in version 7:4.1.8-0+deb10u1.

We recommend that you upgrade your ffmpeg packages.

For the detailed security status of ffmpeg please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/source-package/ffmpeg

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/

Mailing list: debian-security-announce@lists.debian.org

Debian: DSA-4990-1: ffmpeg security update

October 19, 2021
Several vulnerabilities have been discovered in the FFmpeg multimedia framework, which could result in denial of service or potentially the execution of arbitrary code if malformed...

Summary

Several vulnerabilities have been discovered in the FFmpeg multimedia
framework, which could result in denial of service or potentially the
execution of arbitrary code if malformed files/streams are processed.

For the oldstable distribution (buster), these problems have been fixed
in version 7:4.1.8-0+deb10u1.

We recommend that you upgrade your ffmpeg packages.

For the detailed security status of ffmpeg please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/source-package/ffmpeg

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/

Mailing list: debian-security-announce@lists.debian.org

Severity
Package : ffmpeg
CVE ID : CVE-2020-20445 CVE-2020-20446 CVE-2020-20453 CVE-2020-21041
CVE-2020-22015 CVE-2020-22016 CVE-2020-22017 CVE-2020-22019
CVE-2020-22020 CVE-2020-22021 CVE-2020-22022 CVE-2020-22023
CVE-2020-22025 CVE-2020-22026 CVE-2020-22027 CVE-2020-22028
CVE-2020-22029 CVE-2020-22030 CVE-2020-22031 CVE-2020-22032
CVE-2020-22033 CVE-2020-22034 CVE-2020-22035 CVE-2020-22036
CVE-2020-22037 CVE-2020-22049 CVE-2020-22054 CVE-2020-35965
CVE-2021-38114 CVE-2021-38171 CVE-2021-38291

Related News