Jump to content

Advisories MDVSA-2009:297-1: ffmpeg


paul
 Share

Recommended Posts

Vulnerabilities have been discovered and corrected in ffmpeg:

 

- The ffmpeg lavf demuxer allows user-assisted attackers to cause

a denial of service (application crash) via a crafted GIF file

(CVE-2008-3230)

 

- FFmpeg 0.4.9, as used by MPlayer, allows context-dependent attackers

to cause a denial of service (memory consumption) via unknown vectors,

aka a Tcp/udp memory leak. (CVE-2008-4869)

 

- Integer signedness error in the fourxm_read_header function in

libavformat/4xm.c in FFmpeg before revision 16846 allows remote

attackers to execute arbitrary code via a malformed 4X movie file with

a large current_track value, which triggers a NULL pointer dereference

(CVE-2009-0385)

 

The updated packages fix this issue.

 

Update:

 

Packages for 2008.0 are being provided due to extended support for

Corporate products.

Link to comment
Share on other sites

Guest
This topic is now closed to further replies.
 Share

×
×
  • Create New...