Описание
Security update for ffmpeg
This update for ffmpeg fixes the following issues:
Security issues fixed:
- CVE-2019-17542: Fixed a heap-buffer overflow in vqa_decode_chunk due to an out-of-array access (bsc#1154064).
- CVE-2019-12730: Fixed an uninitialized use of variables due to an improper check (bsc#1137526).
- CVE-2019-9718: Fixed a denial of service in the subtitle decode (bsc#1129715).
- CVE-2018-13301: Fixed a denial of service while converting a crafted AVI file to MPEG4 (bsc#1100352).
Список пакетов
SUSE Linux Enterprise Module for Desktop Applications 15
SUSE Linux Enterprise Module for Desktop Applications 15 SP1
SUSE Linux Enterprise Module for Package Hub 15
SUSE Linux Enterprise Workstation Extension 15
SUSE Linux Enterprise Workstation Extension 15 SP1
Ссылки
- Link for SUSE-SU-2019:3184-1
- E-Mail link for SUSE-SU-2019:3184-1
- SUSE Security Ratings
- SUSE Bug 1100352
- SUSE Bug 1129715
- SUSE Bug 1137526
- SUSE Bug 1154064
- SUSE CVE CVE-2018-13301 page
- SUSE CVE CVE-2019-12730 page
- SUSE CVE CVE-2019-17542 page
- SUSE CVE CVE-2019-9718 page
Описание
In FFmpeg 4.0.1, due to a missing check of a profile value before setting it, the ff_mpeg4_decode_picture_header function in libavcodec/mpeg4videodec.c may trigger a NULL pointer dereference while converting a crafted AVI file to MPEG4, leading to a denial of service.
Затронутые продукты
Ссылки
- CVE-2018-13301
- SUSE Bug 1100352
Описание
aa_read_header in libavformat/aadec.c in FFmpeg before 3.2.14 and 4.x before 4.1.4 does not check for sscanf failure and consequently allows use of uninitialized variables.
Затронутые продукты
Ссылки
- CVE-2019-12730
- SUSE Bug 1137526
Описание
FFmpeg before 4.2 has a heap-based buffer overflow in vqa_decode_chunk because of an out-of-array access in vqa_decode_init in libavcodec/vqavideo.c.
Затронутые продукты
Ссылки
- CVE-2019-17542
- SUSE Bug 1154064
Описание
In FFmpeg 3.2 and 4.1, a denial of service in the subtitle decoder allows attackers to hog the CPU via a crafted video file in Matroska format, because ff_htmlmarkup_to_ass in libavcodec/htmlsubtitles.c has a complex format argument to sscanf.
Затронутые продукты
Ссылки
- CVE-2019-9718
- SUSE Bug 1129715