|
|
| |
|
| |
ffmpeg: denial of service/code execution
| Package(s): | ffmpeg |
CVE #(s): | CVE-2011-1196
CVE-2011-2161
CVE-2011-3362
|
| Created: | September 20, 2011 |
Updated: | August 30, 2012 |
| Description: |
From the Ubuntu advisory:
It was discovered that FFmpeg incorrectly handled certain malformed ogg
files. If a user were tricked into opening a crafted ogg file, an attacker
could cause a denial of service via application crash, or possibly execute
arbitrary code with the privileges of the user invoking the program. This
issue only affected Ubuntu 10.10. (CVE-2011-1196)
It was discovered that FFmpeg incorrectly handled certain malformed APE
files. If a user were tricked into opening a crafted APE file, an attacker
could cause a denial of service via application crash. (CVE-2011-2161)
Emmanouel Kellinis discovered that FFmpeg incorrectly handled certain
malformed CAVS files. If a user were tricked into opening a crafted CAVS
file, an attacker could cause a denial of service via application crash, or
possibly execute arbitrary code with the privileges of the user invoking
the program. (CVE-2011-3362)
|
| Alerts: |
|
( Log in to post comments)
|
|
|