Alerts This Week
Warning Icon 1 1,154
Alerts This Week
Warning Icon 1 1,154

Ubuntu 22.04 LTS USN-6449-1 Critical: FFmpeg Memory Leak and DoS

ubuntu
Calendar Grey October 24, 2023
Dist Ubuntu Esm H88
Ubuntu USN-6450-1 outlines significant vulnerabilities in the curl library that impact secure data handling and expose users to potential exploits.
Several security issues were fixed in FFmpeg.

Summary

Several security issues were fixed in FFmpeg.

Software Description:

- ffmpeg: Tools for transcoding, streaming and playing of multimedia files

Details:

It was discovered that FFmpeg incorrectly managed memory resulting

in a memory leak. An attacker could possibly use this issue to cause

a denial of service via application crash. This issue only

affected Ubuntu 18.04 LTS and Ubuntu 20.04 LTS. (CVE-2020-22038)

It was discovered that FFmpeg incorrectly handled certain input files,

leading to an integer overflow. An attacker could possibly use this issue

to cause a denial of service via application crash. This issue only

affected Ubuntu 20.04 LTS. (CVE-2020-20898, CVE-2021-38090,

CVE-2021-38091, CVE-2021-38092, CVE-2021-38093, CVE-2021-38094)

It was discovered that FFmpeg incorrectly managed memory, resulting in

a memory leak. If a user or automated system were tricked into

processing a specially crafted input file, a remote attacker could

possibly use this ...

Read the Full Advisory

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 22.04 LTS (Available with Ubuntu Pro):
   ffmpeg                          7:4.4.2-0ubuntu0.22.04.1+esm2
   libavcodec-extra                7:4.4.2-0ubuntu0.22.04.1+esm2
   libavcodec-extra58              7:4.4.2-0ubuntu0.22.04.1+esm2
   libavcodec58                    7:4.4.2-0ubuntu0.22.04.1+esm2
   libavdevice58                   7:4.4.2-0ubuntu0.22.04.1+esm2
   libavfilter-extra               7:4.4.2-0ubuntu0.22.04.1+esm2
   libavfilter-extra7              7:4.4.2-0ubuntu0.22.04.1+esm2
   libavfilter7                    7:4.4.2-0ubuntu0.22.04.1+esm2
   libavformat-extra               7:4.4.2-0ubuntu0.22.04.1+esm2
   libavformat-extra58             7:4.4.2-0ubuntu0.22.04.1+esm2
   libavformat58                   7:4.4.2-0ubuntu0.22.04.1+esm2
   libavutil56                     7:4.4.2-0ubuntu0.22.04.1+esm2
   libpostproc55                   7:4.4.2-0ubuntu0.22.04.1+esm2
   libswresample3                  7:4.4.2-0ubuntu0.22.04.1+esm2
   libswscale-dev                  7:4.4.2-0ubuntu0.22.04.1+esm2
   libswscale5                     7:4.4.2-0ubuntu0.22.04.1+esm2

Ubuntu 20.04 LTS (Available with Ubuntu Pro):
   ffmpeg                          7:4.2.7-0ubuntu0.1+esm3
   libavcodec-extra                7:4.2.7-0ubuntu0.1+esm3
   libavcodec-extra58              7:4.2.7-0ubuntu0.1+esm3
   libavcodec58                    7:4.2.7-0ubuntu0.1+esm3
   libavdevice58                   7:4.2.7-0ubuntu0.1+esm3
   libavfilter-extra               7:4.2.7-0ubuntu0.1+esm3
   libavfilter-extra7              7:4.2.7-0ubuntu0.1+esm3
   libavfilter7                    7:4.2.7-0ubuntu0.1+esm3
   libavformat58                   7:4.2.7-0ubuntu0.1+esm3
   libavresample4                  7:4.2.7-0ubuntu0.1+esm3
   libavutil56                     7:4.2.7-0ubuntu0.1+esm3
   libpostproc55                   7:4.2.7-0ubuntu0.1+esm3
   libswresample3                  7:4.2.7-0ubuntu0.1+esm3
   libswscale5                     7:4.2.7-0ubuntu0.1+esm3

Ubuntu 18.04 LTS (Available with Ubuntu Pro):
   ffmpeg                          7:3.4.11-0ubuntu0.1+esm3
   libavcodec-extra                7:3.4.11-0ubuntu0.1+esm3
   libavcodec-extra57              7:3.4.11-0ubuntu0.1+esm3
   libavcodec57                    7:3.4.11-0ubuntu0.1+esm3
   libavdevice57                   7:3.4.11-0ubuntu0.1+esm3
   libavfilter-extra               7:3.4.11-0ubuntu0.1+esm3
   libavfilter-extra6              7:3.4.11-0ubuntu0.1+esm3
   libavfilter6                    7:3.4.11-0ubuntu0.1+esm3
   libavformat57                   7:3.4.11-0ubuntu0.1+esm3
   libavresample3                  7:3.4.11-0ubuntu0.1+esm3
   libavutil55                     7:3.4.11-0ubuntu0.1+esm3
   libpostproc54                   7:3.4.11-0ubuntu0.1+esm3
   libswresample2                  7:3.4.11-0ubuntu0.1+esm3
   libswscale4                     7:3.4.11-0ubuntu0.1+esm3

In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-6449-1

CVE-2020-20898, CVE-2020-22038, CVE-2021-38090, CVE-2021-38091,

CVE-2021-38092, CVE-2021-38093, CVE-2021-38094, CVE-2022-48434

Severity
critical
Lowest
Low
Medium
High
Critical

Ubuntu Security Notice USN-6449-1

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here