Alerts This Week
Warning Icon 1 560
Alerts This Week
Warning Icon 1 560

openSUSE Leap 15.3 2021:2322-1 Important: ffmpeg Buffer Overflow Fix

opensuse
Calendar Grey July 14, 2021
Dist Opensuse Esm H88
Tackling 19 significant security flaws, the new Fedora GIMP upgrade boosts platform reliability and protection.
An update that fixes 23 vulnerabilities is now available

Description

This update for ffmpeg fixes the following issues:

- CVE-2020-13904: Fixed use-after-free via a crafted EXTINF duration in an

m3u8 file (bsc#1172640).

- CVE-2020-21041: Fixed buffer overflow vulnerability via

apng_do_inverse_blend in libavcodec/pngenc.c (bsc#1186406).

- CVE-2019-17539: Fixed NULL pointer dereference in avcodec_open2 in

libavcodec/utils.c (bsc# 1154065).

- CVE-2020-22026: Fixed buffer overflow vulnerability in config_input() at

libavfilter/af_tremolo.c (bsc#1186583).

- CVE-2020-22021: Fixed buffer overflow vulnerability in filter_edges

function in libavfilter/vf_yadif.c (bsc#1186586).

- CVE-2020-22020: Fixed buffer overflow vulnerability in build_diff_map()

in libavfilter/vf_fieldmatch.c (bsc#1186587).

- CVE-2020-22015: Fixed buffer overflow vulnerability in

mov_write_video_tag() due to the out of bounds in libavformat/movenc.c

(bsc#1186596).

- CVE-2020-22016: Fixed a heap-based Buffer Overflow...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Leap 15.3:

zypper in -t patch openSUSE-SLE-15.3-2021-2322=1

Package List

- openSUSE Leap 15.3 (aarch64 ppc64le s390x x86_64):

ffmpeg-3.4.2-11.3.1

ffmpeg-debuginfo-3.4.2-11.3.1

ffmpeg-debugsource-3.4.2-11.3.1

ffmpeg-private-devel-3.4.2-11.3.1

libavcodec-devel-3.4.2-11.3.1

libavcodec57-3.4.2-11.3.1

libavcodec57-debuginfo-3.4.2-11.3.1

libavdevice-devel-3.4.2-11.3.1

libavdevice57-3.4.2-11.3.1

libavdevice57-debuginfo-3.4.2-11.3.1

libavfilter-devel-3.4.2-11.3.1

libavfilter6-3.4.2-11.3.1

libavfilter6-debuginfo-3.4.2-11.3.1

libavformat-devel-3.4.2-11.3.1

libavformat57-3.4.2-11.3.1

libavformat57-debuginfo-3.4.2-11.3.1

libavresample-devel-3.4.2-11.3.1

libavresample3-3.4.2-11.3.1

libavresample3-debuginfo-3.4.2-11.3.1

libavutil-devel-3.4.2-11.3.1

libavutil55-3.4.2-11.3.1

libavutil55-debuginfo-3.4.2-11.3.1

libpostproc-devel-3.4.2-11.3.1

libpostproc54-3.4.2-11.3.1

libpostproc54-debuginfo-3.4.2-11.3.1

libswresample-devel-3.4.2-11.3.1

libswresample2-3.4.2-11.3.1

libswresample2-debuginfo-3.4.2-11.3.1

libswscale-devel-3.4.2-11.3.1

libswscale4-3.4.2-11.3.1

libswscale4-debuginfo-3.4.2-11.3.1

- openSUSE Leap...

Read the Full Advisory

References

https://www.suse.com/security/cve/CVE-2019-17539.html

https://www.suse.com/security/cve/CVE-2020-13904.html

https://www.suse.com/security/cve/CVE-2020-20448.html

https://www.suse.com/security/cve/CVE-2020-20451.html

https://https://www.suse.com/security/cve/CVE-2020-21041.html

https://www.suse.com/security/cve/CVE-2020-22015.html

https://www.suse.com/security/cve/CVE-2020-22016.html

https://www.suse.com/security/cve/CVE-2020-22017.html

https://www.suse.com/security/cve/CVE-2020-22019.html

https://www.suse.com/security/cve/CVE-2020-22020.html

https://www.suse.com/security/cve/CVE-2020-22021.html

https://www.suse.com/security/cve/CVE-2020-22022.html

https://www.suse.com/security/cve/CVE-2020-22023.html

https://www.suse.com/security/cve/CVE-2020-22025.html

https://www.suse.com/security/cve/CVE-2020-22026.html

https://www.suse.com/security/cve/CVE-2020-22031.html

https://www.suse.com/security/cve/CVE-2020-22032.html

https://www.suse.com/security/cve/CVE-2020-22033.html

https://www.suse.com/security/cve/CVE-...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2021:2322-1
Rating: important
Affected Products: openSUSE Leap 15.3 .

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here