LWN.net Logo

ffmpeg: multiple vulnerabilities

Package(s):ffmpeg CVE #(s):CVE-2011-3929 CVE-2011-3936 CVE-2011-3940 CVE-2011-3947 CVE-2012-0853 CVE-2012-0947
Created:May 14, 2012 Updated:August 20, 2012
Description: From the Debian advisory:

Several vulnerabilities have been discovered in FFmpeg, a multimedia player, server and encoder. Multiple input validations in the decoders/ demuxers for Westwood Studios VQA, Apple MJPEG-B, Theora, Matroska, Vorbis, Sony ATRAC3, DV, NSV, files could lead to the execution of arbitrary code.

Alerts:
Debian DSA-2471-1 2012-05-13
Mandriva MDVSA-2012:076 2012-05-15
Ubuntu USN-1478-1 2012-06-18
Ubuntu USN-1479-1 2012-06-18
Mageia MGASA-2012-0141 2012-07-09
Mageia MGASA-2012-0142 2012-07-09
Mageia MGASA-2012-0204 2012-08-06
Mageia MGASA-2012-0218 2012-08-18
Gentoo 201210-06 2012-10-19

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds