Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 461
Alerts This Week
Warning Icon 1 461

Ubuntu 10.04 LTS: USN-1479-1 Moderate: FFmpeg Denial Of Service

ubuntu
Calendar Grey June 18, 2012
Scroller Ubuntu
Security flaws in FFmpeg on Ubuntu 10.04 LTS might result in software crashes or allow for unauthorized command execution when specially crafted files are accessed.
FFmpeg could be made to crash or run programs as your login if it opened a specially crafted file.

Summary

FFmpeg could be made to crash or run programs as your login if it

opened a specially crafted file.

Software Description:

- ffmpeg: multimedia player, server and encoder

Details:

Mateusz Jurczyk and Gynvael Coldwind discovered that FFmpeg incorrectly

handled certain malformed DV files. If a user were tricked into opening a

crafted DV file, an attacker could cause a denial of service via

application crash, or possibly execute arbitrary code with the privileges

of the user invoking the program. (CVE-2011-3929, CVE-2011-3936)

Mateusz Jurczyk and Gynvael Coldwind discovered that FFmpeg incorrectly

handled certain malformed NSV files. If a user were tricked into opening a

crafted NSV file, an attacker could cause a denial of service via

application crash, or possibly execute arbitrary code with the privileges

of the user invoking the program. (CVE-2011-3940)

Mateusz Jurczyk and Gynvael Coldwind discovered that FFmpeg incorrectly

handled certain malformed MJPEG-...

Read the Full Advisory

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 10.04 LTS:
  libavcodec52                    4:0.5.9-0ubuntu0.10.04.1
  libavformat52                   4:0.5.9-0ubuntu0.10.04.1

This update uses a new upstream release of Libav, which includes additional
bug fixes. In general, a standard system update will make all the necessary
changes.

References

https://ubuntu.com/security/notices/USN-1479-1

CVE-2011-3929, CVE-2011-3936, CVE-2011-3940, CVE-2011-3947,

CVE-2011-3951, CVE-2011-3952, CVE-2012-0851, CVE-2012-0852,

CVE-2012-0853, CVE-2012-0858, CVE-2012-0859, CVE-2012-0947

Severity
important
Lowest
Low
Medium
High
Critical

June 18, 2012

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.