MGASA-2024-0283 - Updated ffmpeg packages fix security vulnerabilities

Publication date: 09 Sep 2024
URL: https://advisories.mageia.org/MGASA-2024-0283.html
Type: security
Affected Mageia releases: 9
CVE: CVE-2024-7055,
     CVE-2024-7272

A vulnerability was found in FFmpeg up to 7.0.1. It has been classified
as critical. This affects the function pnm_decode_frame in the library
/libavcodec/pnmdec.c. The manipulation leads to heap-based buffer
overflow. It is possible to initiate the attack remotely. The exploit
has been disclosed to the public and may be used. (CVE-2024-7055)
A vulnerability, which was classified as critical, was found in FFmpeg
up to 5.1.5. This affects the function fill_audiodata of the file
/libswresample/swresample.c. The manipulation leads to heap-based buffer
overflow. It is possible to initiate the attack remotely.
(CVE-2024-7272)

References:
- https://bugs.mageia.org/show_bug.cgi?id=33524
- https://lwn.net/Articles/985600/
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-7055
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-7272

SRPMS:
- 9/core/ffmpeg-5.1.6-1.mga9
- 9/tainted/ffmpeg-5.1.6-1.mga9.tainted

Mageia 2024-0283: ffmpeg Security Advisory Updates

A vulnerability was found in FFmpeg up to 7.0.1

Summary

A vulnerability was found in FFmpeg up to 7.0.1. It has been classified as critical. This affects the function pnm_decode_frame in the library /libavcodec/pnmdec.c. The manipulation leads to heap-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. (CVE-2024-7055) A vulnerability, which was classified as critical, was found in FFmpeg up to 5.1.5. This affects the function fill_audiodata of the file /libswresample/swresample.c. The manipulation leads to heap-based buffer overflow. It is possible to initiate the attack remotely. (CVE-2024-7272)

References

- https://bugs.mageia.org/show_bug.cgi?id=33524

- https://lwn.net/Articles/985600/

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-7055

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-7272

Resolution

MGASA-2024-0283 - Updated ffmpeg packages fix security vulnerabilities

SRPMS

- 9/core/ffmpeg-5.1.6-1.mga9

- 9/tainted/ffmpeg-5.1.6-1.mga9.tainted

Severity
Publication date: 09 Sep 2024
URL: https://advisories.mageia.org/MGASA-2024-0283.html
Type: security
CVE: CVE-2024-7055, CVE-2024-7272

Related News