Alerts This Week
Warning Icon 1 537
Alerts This Week
Warning Icon 1 537

openSUSE Leap 15.3: 2021:2919-1 Important: FFmpeg Denial Of Service Issues

opensuse
Calendar Grey September 2, 2021
Dist Opensuse Esm H88
New patch released for openSUSE addressing 8 critical vulnerabilities in ffmpeg, including risks of denial of service.
An update that fixes 8 vulnerabilities is now available

Description

This update for ffmpeg fixes the following issues:

- CVE-2019-9721: Fix denial of service in the subtitle decoder in

handle_open_brace from libavcodec/htmlsubtitles.c (bsc#1129714).

- CVE-2020-22046: Fix a denial of service vulnerability exists in FFmpeg

4.2 due to a memory leak in the avpriv_float_dsp_allocl function in

libavutil/float_dsp.c (bsc#1186849).

- CVE-2020-22048: Fix a denial of service vulnerability exists in FFmpeg

4.2 due to a memory leak in the ff_frame_pool_get function in

framepool.c (bsc#1186859).

- CVE-2020-22049: Fix a denial of service vulnerability exists in FFmpeg

4.2 due to a memory leak in the wtvfile_open_sector function in wtvdec.c

(bsc#1186861).

- CVE-2020-22054: Fix a denial of service vulnerability exists in FFmpeg

4.2 due to a memory leak in the av_dict_set function in dict.c

(bsc#1186863).

- CVE-2020-21688: Fixed a heap-use-after-free in the av_freep function in

libavutil/mem.c...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Leap 15.3:

zypper in -t patch openSUSE-SLE-15.3-2021-2919=1

Package List

- openSUSE Leap 15.3 (aarch64 ppc64le s390x x86_64):

ffmpeg-3.4.2-11.8.2

ffmpeg-debuginfo-3.4.2-11.8.2

ffmpeg-debugsource-3.4.2-11.8.2

ffmpeg-private-devel-3.4.2-11.8.2

libavcodec-devel-3.4.2-11.8.2

libavcodec57-3.4.2-11.8.2

libavcodec57-debuginfo-3.4.2-11.8.2

libavdevice-devel-3.4.2-11.8.2

libavdevice57-3.4.2-11.8.2

libavdevice57-debuginfo-3.4.2-11.8.2

libavfilter-devel-3.4.2-11.8.2

libavfilter6-3.4.2-11.8.2

libavfilter6-debuginfo-3.4.2-11.8.2

libavformat-devel-3.4.2-11.8.2

libavformat57-3.4.2-11.8.2

libavformat57-debuginfo-3.4.2-11.8.2

libavresample-devel-3.4.2-11.8.2

libavresample3-3.4.2-11.8.2

libavresample3-debuginfo-3.4.2-11.8.2

libavutil-devel-3.4.2-11.8.2

libavutil55-3.4.2-11.8.2

libavutil55-debuginfo-3.4.2-11.8.2

libpostproc-devel-3.4.2-11.8.2

libpostproc54-3.4.2-11.8.2

libpostproc54-debuginfo-3.4.2-11.8.2

libswresample-devel-3.4.2-11.8.2

libswresample2-3.4.2-11.8.2

libswresample2-debuginfo-3.4.2-11.8.2

libswscale-devel-3.4.2-11.8.2

libswscale4-3.4.2-11.8.2

libswscale4-debuginfo-3.4.2-11.8.2

- openSUSE Leap...

Read the Full Advisory

References

https://www.suse.com/security/cve/CVE-2019-9721.html

https://www.suse.com/security/cve/CVE-2020-21688.html

https://www.suse.com/security/cve/CVE-2020-21697.html

https://www.suse.com/security/cve/CVE-2020-22046.html

https://www.suse.com/security/cve/CVE-2020-22048.html

https://www.suse.com/security/cve/CVE-2020-22049.html

https://www.suse.com/security/cve/CVE-2020-22054.html

https://www.suse.com/security/cve/CVE-2021-38114.html

https://bugzilla.suse.com/1129714

https://bugzilla.suse.com/1186849

https://bugzilla.suse.com/1186859

https://bugzilla.suse.com/1186861

https://bugzilla.suse.com/1186863

https://bugzilla.suse.com/1189142

https://bugzilla.suse.com/1189348

https://bugzilla.suse.com/1189350

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2021:2919-1
Rating: important
Affected Products: openSUSE Leap 15.3 .

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here