security advisorydenial of servicebuffer overflow
A heap-based buffer overflow flaw in the decoding functions of openh264, a codec library which supports H.264 encoding and decoding, may allow a remote attacker to cause a denial of service or the execution of arbitrary code if a specially crafted video is processed. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-5870-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Salvatore Bonaccorso February 26, 2025 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : openh264 CVE ID : CVE-2025-27091 Debian Bug : 1098470 A heap-based buffer overflow flaw in the decoding functions of openh264, a codec library which supports H.264 encoding and decoding, may allow a remote attacker to cause a denial of service or the execution of arbitrary code if a specially crafted video is processed. For the stable distribution (bookworm), this problem has been fixed in version 2.3.1+dfsg-3+deb12u1. We recommend that you upgrade your openh264 packages. For the detailed security status of openh264 please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/openh264 Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Ubuntu Security Notice USN-5820-1 brings attention to a critical vulnerability in libavcodec, advising users to apply updates for improved safety and performance.. buffer overflow, openh264, security advisory, Debian updates. . Severity: Critical. LinuxSecurity.com Team
Feb 26, 2025
•Critical
Debian