LWN.net Logo

ffmpeg: denial of service/code execution

Package(s):ffmpeg CVE #(s):CVE-2011-1196 CVE-2011-2161 CVE-2011-3362
Created:September 20, 2011 Updated:August 30, 2012
Description: From the Ubuntu advisory:

It was discovered that FFmpeg incorrectly handled certain malformed ogg files. If a user were tricked into opening a crafted ogg file, an attacker could cause a denial of service via application crash, or possibly execute arbitrary code with the privileges of the user invoking the program. This issue only affected Ubuntu 10.10. (CVE-2011-1196)

It was discovered that FFmpeg incorrectly handled certain malformed APE files. If a user were tricked into opening a crafted APE file, an attacker could cause a denial of service via application crash. (CVE-2011-2161)

Emmanouel Kellinis discovered that FFmpeg incorrectly handled certain malformed CAVS files. If a user were tricked into opening a crafted CAVS file, an attacker could cause a denial of service via application crash, or possibly execute arbitrary code with the privileges of the user invoking the program. (CVE-2011-3362)

Alerts:
Debian DSA-2336-1 2011-11-07
Ubuntu USN-1209-2 2011-09-19
Ubuntu USN-1209-1 2011-09-19
Mandriva MDVSA-2012:074 2012-05-14
Mandriva MDVSA-2012:075 2012-05-15
Mandriva MDVSA-2012:076 2012-05-15
Mandriva MDVSA-2012:074-1 2012-08-30
Mandriva MDVSA-2012:148 2012-08-30

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds