Описание
Security update for ffmpeg-4
This update for ffmpeg-4 fixes the following issues:
- CVE-2024-32230: Fixed buffer overflow due to negative-size-param bug in load_input_picture() (bsc#1227296).
- CVE-2023-51798: Fixed buffer overflow via a floating point exception (FPE) error at libavfilter/vf_minterpolate.c (bsc#1223304).
Список пакетов
Container containers/open-webui:0
ffmpeg-4-4.4-150600.13.10.1
libavcodec58_134-4.4-150600.13.10.1
libavdevice58_13-4.4-150600.13.10.1
libavfilter7_110-4.4-150600.13.10.1
libavformat58_76-4.4-150600.13.10.1
libavresample4_0-4.4-150600.13.10.1
libavutil56_70-4.4-150600.13.10.1
libpostproc55_9-4.4-150600.13.10.1
libswresample3_9-4.4-150600.13.10.1
libswscale5_9-4.4-150600.13.10.1
SUSE Linux Enterprise Module for Package Hub 15 SP6
ffmpeg-4-4.4-150600.13.10.1
ffmpeg-4-libavcodec-devel-4.4-150600.13.10.1
ffmpeg-4-libavdevice-devel-4.4-150600.13.10.1
ffmpeg-4-libavfilter-devel-4.4-150600.13.10.1
ffmpeg-4-libavformat-devel-4.4-150600.13.10.1
ffmpeg-4-libavresample-devel-4.4-150600.13.10.1
ffmpeg-4-libavutil-devel-4.4-150600.13.10.1
ffmpeg-4-libpostproc-devel-4.4-150600.13.10.1
ffmpeg-4-libswresample-devel-4.4-150600.13.10.1
ffmpeg-4-libswscale-devel-4.4-150600.13.10.1
ffmpeg-4-private-devel-4.4-150600.13.10.1
libavcodec58_134-4.4-150600.13.10.1
libavdevice58_13-4.4-150600.13.10.1
libavfilter7_110-4.4-150600.13.10.1
libavformat58_76-4.4-150600.13.10.1
libavresample4_0-4.4-150600.13.10.1
libavutil56_70-4.4-150600.13.10.1
libpostproc55_9-4.4-150600.13.10.1
libswresample3_9-4.4-150600.13.10.1
libswscale5_9-4.4-150600.13.10.1
SUSE Linux Enterprise Workstation Extension 15 SP6
libavcodec58_134-4.4-150600.13.10.1
libavformat58_76-4.4-150600.13.10.1
libavutil56_70-4.4-150600.13.10.1
libswresample3_9-4.4-150600.13.10.1
libswscale5_9-4.4-150600.13.10.1
openSUSE Leap 15.6
ffmpeg-4-4.4-150600.13.10.1
ffmpeg-4-libavcodec-devel-4.4-150600.13.10.1
ffmpeg-4-libavdevice-devel-4.4-150600.13.10.1
ffmpeg-4-libavfilter-devel-4.4-150600.13.10.1
ffmpeg-4-libavformat-devel-4.4-150600.13.10.1
ffmpeg-4-libavresample-devel-4.4-150600.13.10.1
ffmpeg-4-libavutil-devel-4.4-150600.13.10.1
ffmpeg-4-libpostproc-devel-4.4-150600.13.10.1
ffmpeg-4-libswresample-devel-4.4-150600.13.10.1
ffmpeg-4-libswscale-devel-4.4-150600.13.10.1
ffmpeg-4-private-devel-4.4-150600.13.10.1
libavcodec58_134-4.4-150600.13.10.1
libavcodec58_134-32bit-4.4-150600.13.10.1
libavdevice58_13-4.4-150600.13.10.1
libavdevice58_13-32bit-4.4-150600.13.10.1
libavfilter7_110-4.4-150600.13.10.1
libavfilter7_110-32bit-4.4-150600.13.10.1
libavformat58_76-4.4-150600.13.10.1
libavformat58_76-32bit-4.4-150600.13.10.1
libavresample4_0-4.4-150600.13.10.1
libavresample4_0-32bit-4.4-150600.13.10.1
libavutil56_70-4.4-150600.13.10.1
libavutil56_70-32bit-4.4-150600.13.10.1
libpostproc55_9-4.4-150600.13.10.1
libpostproc55_9-32bit-4.4-150600.13.10.1
libswresample3_9-4.4-150600.13.10.1
libswresample3_9-32bit-4.4-150600.13.10.1
libswscale5_9-4.4-150600.13.10.1
libswscale5_9-32bit-4.4-150600.13.10.1
Ссылки
- Link for SUSE-SU-2024:2864-1
- E-Mail link for SUSE-SU-2024:2864-1
- SUSE Security Ratings
- SUSE Bug 1223304
- SUSE Bug 1227296
- SUSE CVE CVE-2023-51798 page
- SUSE CVE CVE-2024-32230 page
Описание
Buffer Overflow vulnerability in Ffmpeg v.N113007-g8d24a28d06 allows a local attacker to execute arbitrary code via a floating point exception (FPE) error at libavfilter/vf_minterpolate.c:1078:60 in interpolate.
Затронутые продукты
Container containers/open-webui:0:ffmpeg-4-4.4-150600.13.10.1
Container containers/open-webui:0:libavcodec58_134-4.4-150600.13.10.1
Container containers/open-webui:0:libavdevice58_13-4.4-150600.13.10.1
Container containers/open-webui:0:libavfilter7_110-4.4-150600.13.10.1
Ссылки
- CVE-2023-51798
- SUSE Bug 1223304
Описание
FFmpeg 7.0 is vulnerable to Buffer Overflow. There is a negative-size-param bug at libavcodec/mpegvideo_enc.c:1216:21 in load_input_picture in FFmpeg7.0
Затронутые продукты
Container containers/open-webui:0:ffmpeg-4-4.4-150600.13.10.1
Container containers/open-webui:0:libavcodec58_134-4.4-150600.13.10.1
Container containers/open-webui:0:libavdevice58_13-4.4-150600.13.10.1
Container containers/open-webui:0:libavfilter7_110-4.4-150600.13.10.1
Ссылки
- CVE-2024-32230
- SUSE Bug 1227296