Описание
Security update for ffmpeg-4
This update for ffmpeg-4 fixes the following issues:
- CVE-2024-36618: Fixed integer overflow iff ULONG_MAX < INT64_MAX (bsc#1234020).
- CVE-2025-7700: Fixed potential NULL pointer dereference (bsc#1246790).
Список пакетов
Image SLES15-SP4-SAP-Azure-LI-BYOS
libavcodec58_134-4.4.6-150400.3.52.1
libavutil56_70-4.4.6-150400.3.52.1
libswresample3_9-4.4.6-150400.3.52.1
Image SLES15-SP4-SAP-Azure-LI-BYOS-Production
libavcodec58_134-4.4.6-150400.3.52.1
libavutil56_70-4.4.6-150400.3.52.1
libswresample3_9-4.4.6-150400.3.52.1
Image SLES15-SP4-SAP-Azure-VLI-BYOS
libavcodec58_134-4.4.6-150400.3.52.1
libavutil56_70-4.4.6-150400.3.52.1
libswresample3_9-4.4.6-150400.3.52.1
Image SLES15-SP4-SAP-Azure-VLI-BYOS-Production
libavcodec58_134-4.4.6-150400.3.52.1
libavutil56_70-4.4.6-150400.3.52.1
libswresample3_9-4.4.6-150400.3.52.1
SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS
libavcodec58_134-4.4.6-150400.3.52.1
libavformat58_76-4.4.6-150400.3.52.1
libavutil56_70-4.4.6-150400.3.52.1
libpostproc55_9-4.4.6-150400.3.52.1
libswresample3_9-4.4.6-150400.3.52.1
libswscale5_9-4.4.6-150400.3.52.1
SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS
libavcodec58_134-4.4.6-150400.3.52.1
libavformat58_76-4.4.6-150400.3.52.1
libavutil56_70-4.4.6-150400.3.52.1
libpostproc55_9-4.4.6-150400.3.52.1
libswresample3_9-4.4.6-150400.3.52.1
libswscale5_9-4.4.6-150400.3.52.1
SUSE Linux Enterprise Server 15 SP4-LTSS
libavcodec58_134-4.4.6-150400.3.52.1
libavformat58_76-4.4.6-150400.3.52.1
libavutil56_70-4.4.6-150400.3.52.1
libpostproc55_9-4.4.6-150400.3.52.1
libswresample3_9-4.4.6-150400.3.52.1
libswscale5_9-4.4.6-150400.3.52.1
SUSE Linux Enterprise Server for SAP Applications 15 SP4
libavcodec58_134-4.4.6-150400.3.52.1
libavformat58_76-4.4.6-150400.3.52.1
libavutil56_70-4.4.6-150400.3.52.1
libpostproc55_9-4.4.6-150400.3.52.1
libswresample3_9-4.4.6-150400.3.52.1
libswscale5_9-4.4.6-150400.3.52.1
Ссылки
- Link for SUSE-SU-2025:02972-1
- E-Mail link for SUSE-SU-2025:02972-1
- SUSE Security Ratings
- SUSE Bug 1234018
- SUSE Bug 1234019
- SUSE Bug 1234020
- SUSE Bug 1245313
- SUSE Bug 1246790
- SUSE CVE CVE-2024-36618 page
- SUSE CVE CVE-2025-7700 page
Описание
FFmpeg n6.1.1 has a vulnerability in the AVI demuxer of the libavformat library which allows for an integer overflow, potentially resulting in a denial-of-service (DoS) condition.
Затронутые продукты
Image SLES15-SP4-SAP-Azure-LI-BYOS-Production:libavcodec58_134-4.4.6-150400.3.52.1
Image SLES15-SP4-SAP-Azure-LI-BYOS-Production:libavutil56_70-4.4.6-150400.3.52.1
Image SLES15-SP4-SAP-Azure-LI-BYOS-Production:libswresample3_9-4.4.6-150400.3.52.1
Image SLES15-SP4-SAP-Azure-LI-BYOS:libavcodec58_134-4.4.6-150400.3.52.1
Ссылки
- CVE-2024-36618
- SUSE Bug 1234020
Описание
A flaw was found in FFmpeg's ALS audio decoder, where it does not properly check for memory allocation failures. This can cause the application to crash when processing certain malformed audio files. While it does not lead to data theft or system control, it can be used to disrupt services and cause a denial of service.
Затронутые продукты
Image SLES15-SP4-SAP-Azure-LI-BYOS-Production:libavcodec58_134-4.4.6-150400.3.52.1
Image SLES15-SP4-SAP-Azure-LI-BYOS-Production:libavutil56_70-4.4.6-150400.3.52.1
Image SLES15-SP4-SAP-Azure-LI-BYOS-Production:libswresample3_9-4.4.6-150400.3.52.1
Image SLES15-SP4-SAP-Azure-LI-BYOS:libavcodec58_134-4.4.6-150400.3.52.1
Ссылки
- CVE-2025-7700
- SUSE Bug 1246790