Alerts This Week
Warning Icon 1 637
Alerts This Week
Warning Icon 1 637

Debian 11: DLA-4039-1 critical: ffmpeg integer overflows and double-free

debian lts
Calendar Grey February 1, 2025
Dist Debian Esm H88
The Debian Security Advisory DLA-4039-1 highlights vulnerabilities within ffmpeg that involve integer overflow and double-free conditions in error handling.
Several issues have been found in ffmpeg, a package that contains tools for transcoding, streaming and playing of multimedia files Those issues are related to possible integer over...

Summary

Several issues have been found in ffmpeg, a package that contains tools
for transcoding, streaming and playing of multimedia files
Those issues are related to possible integer overflows, double-free on
errors and out-of-bounds access.


For Debian 11 bullseye, these problems have been fixed in version
7:4.3.8-0+deb11u2.

We recommend that you upgrade your ffmpeg packages.

For the detailed security status of ffmpeg please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/source-package/ffmpeg

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS

(I had to resend this email, so sorry if you are getting this twice)


Severity
critical
Lowest
Low
Medium
High
Critical

Package: ffmpeg
Version: 7:4.3.8-0+deb11u2
CVE ID: CVE-2024-35367 CVE-2024-35368 CVE-2024-36618

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here