[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248364

 
 

909

 
 

195388

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-2306-1 ffmpeg -- several issues

ID: oval:org.secpod.oval:def:600616Date: (C)2011-10-13   (M)2023-11-09
Class: PATCHFamily: unix




Several vulnerabilities have been discovered in ffmpeg, a multimedia player, server and encoder. The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2010-3908 FFmpeg before 0.5.4, allows remote attackers to cause a denial of service or possibly execute arbitrary code via a malformed WMV file. CVE-2010-4704 libavcodec/vorbis_dec.c in the Vorbis decoder in FFmpeg allows remote attackers to cause a denial of service via a crafted .ogg file, related to the vorbis_floor0_decode function. CVE-2011-0480 Multiple buffer overflows in vorbis_dec.c in the Vorbis decoder in FFmpeg allow remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted WebM file, related to buffers for the channel floor and the channel residue. CVE-2011-0722 FFmpeg allows remote attackers to cause a denial of service or possibly execute arbitrary code via a malformed RealMedia file.

Platform:
Debian 6.0
Product:
ffmpeg
Reference:
DSA-2306-1
CVE-2010-3908
CVE-2010-4704
CVE-2011-0480
CVE-2011-0722
CVE-2011-0723
CVE    5
CVE-2011-0722
CVE-2011-0723
CVE-2011-0480
CVE-2010-3908
...
CPE    23
cpe:/o:debian:debian_linux:6.x
cpe:/a:ffmpeg:ffmpeg:0.3
cpe:/a:ffmpeg:ffmpeg:0.4.9:pre1
cpe:/a:ffmpeg:ffmpeg:0.5
...

© SecPod Technologies