LWN.net Logo

ffmpeg: multiple vulnerabilities

Package(s):ffmpeg CVE #(s):CVE-2010-3908 CVE-2011-0480 CVE-2011-0722 CVE-2011-0723
Created:April 4, 2011 Updated:September 12, 2011
Description: From the Mandriva advisory:

Fix memory corruption in WMV parsing (CVE-2010-3908)

Multiple buffer overflows in vorbis_dec.c in the Vorbis decoder in FFmpeg, as used in Google Chrome before 8.0.552.237 and Chrome OS before 8.0.552.344, allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact via a crafted WebM file, related to buffers for (1) the channel floor and (2) the channel residue. (CVE-2011-0480)

Fix heap corruption crashes (CVE-2011-0722)

Fix invalid reads in VC-1 decoding (CVE-2011-0723)

Alerts:
Debian DSA-2306-1 2011-09-11
Mandriva MDVSA-2011:114 2011-07-18
Mandriva MDVSA-2011:112 2011-07-18
Ubuntu USN-1104-1 2011-04-04
Mandriva MDVSA-2011:062 2011-04-01
Mandriva MDVSA-2011:061 2011-04-01
Mandriva MDVSA-2011:089 2011-05-16

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds