LWN.net Logo

ffmpeg: several vulnerabilities

Package(s):ffmpeg, ffmpeg-debian CVE #(s):CVE-2008-4610 CVE-2009-0385
Created:March 17, 2009 Updated:December 17, 2009
Description: From the Ubuntu advisory:

It was discovered that FFmpeg did not correctly handle certain malformed Ogg Media (OGM) files. If a user were tricked into opening a crafted Ogg Media file, an attacker could cause the application using FFmpeg to crash, leading to a denial of service.

It was discovered that FFmpeg did not correctly handle certain malformed 4X movie (4xm) files. If a user were tricked into opening a crafted 4xm file, an attacker could execute arbitrary code with the privileges of the user invoking the program.

Alerts:
Mandriva MDVSA-2009:335 2009-12-17
Mandriva MDVSA-2009:319 2009-12-05
Mandriva MDVSA-2009:297-1 2009-12-05
Mandriva MDVSA-2009:297 2009-11-13
Mandriva MDVSA-2009:298 2009-11-13
Mandriva MDVSA-2009:299 2009-11-13
Debian DSA-1782-1 2009-04-29
Debian DSA-1781-1 2009-04-29
Fedora FEDORA-2009-3433 2009-04-09
Fedora FEDORA-2009-3428 2009-04-09
Slackware SSA:2009-098-03 2009-04-08
Gentoo 200903-33 2009-03-19
Ubuntu USN-734-1 2009-03-16

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds