ffmpeg: multiple vulnerabilities
| Package(s): | ffmpeg | CVE #(s): | CVE-2010-3908 CVE-2011-0480 CVE-2011-0722 CVE-2011-0723 | ||||||||||||||||||||||||||||||||
| Created: | April 4, 2011 | Updated: | September 12, 2011 | ||||||||||||||||||||||||||||||||
| Description: | From the Mandriva advisory:
Fix memory corruption in WMV parsing (CVE-2010-3908) Multiple buffer overflows in vorbis_dec.c in the Vorbis decoder in FFmpeg, as used in Google Chrome before 8.0.552.237 and Chrome OS before 8.0.552.344, allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact via a crafted WebM file, related to buffers for (1) the channel floor and (2) the channel residue. (CVE-2011-0480) Fix heap corruption crashes (CVE-2011-0722) Fix invalid reads in VC-1 decoding (CVE-2011-0723) | ||||||||||||||||||||||||||||||||||
| Alerts: |
| ||||||||||||||||||||||||||||||||||
