Описание
Security update for ffmpeg
This update for ffmpeg fixes the following issues:
- CVE-2025-7700: Fixed NULL Pointer Dereference in FFmpeg ALS Decoder (libavcodec/alsdec.c) (bsc#1246790).
Список пакетов
SUSE Linux Enterprise Module for Desktop Applications 15 SP6
libavcodec57-3.4.2-150200.11.67.1
libavutil-devel-3.4.2-150200.11.67.1
libavutil55-3.4.2-150200.11.67.1
libpostproc-devel-3.4.2-150200.11.67.1
libpostproc54-3.4.2-150200.11.67.1
libswresample-devel-3.4.2-150200.11.67.1
libswresample2-3.4.2-150200.11.67.1
libswscale-devel-3.4.2-150200.11.67.1
libswscale4-3.4.2-150200.11.67.1
SUSE Linux Enterprise Module for Desktop Applications 15 SP7
libavcodec57-3.4.2-150200.11.67.1
libavutil-devel-3.4.2-150200.11.67.1
libavutil55-3.4.2-150200.11.67.1
libpostproc-devel-3.4.2-150200.11.67.1
libpostproc54-3.4.2-150200.11.67.1
libswresample-devel-3.4.2-150200.11.67.1
libswresample2-3.4.2-150200.11.67.1
libswscale-devel-3.4.2-150200.11.67.1
libswscale4-3.4.2-150200.11.67.1
SUSE Linux Enterprise Module for Package Hub 15 SP6
ffmpeg-3.4.2-150200.11.67.1
libavdevice57-3.4.2-150200.11.67.1
libavfilter6-3.4.2-150200.11.67.1
libavformat57-3.4.2-150200.11.67.1
libavresample3-3.4.2-150200.11.67.1
SUSE Linux Enterprise Module for Package Hub 15 SP7
ffmpeg-3.4.2-150200.11.67.1
libavdevice57-3.4.2-150200.11.67.1
libavfilter6-3.4.2-150200.11.67.1
libavformat57-3.4.2-150200.11.67.1
libavresample3-3.4.2-150200.11.67.1
SUSE Linux Enterprise Workstation Extension 15 SP6
libavcodec-devel-3.4.2-150200.11.67.1
libavformat-devel-3.4.2-150200.11.67.1
libavformat57-3.4.2-150200.11.67.1
libavresample-devel-3.4.2-150200.11.67.1
libavresample3-3.4.2-150200.11.67.1
SUSE Linux Enterprise Workstation Extension 15 SP7
libavcodec-devel-3.4.2-150200.11.67.1
libavformat-devel-3.4.2-150200.11.67.1
libavformat57-3.4.2-150200.11.67.1
libavresample-devel-3.4.2-150200.11.67.1
libavresample3-3.4.2-150200.11.67.1
openSUSE Leap 15.6
ffmpeg-3.4.2-150200.11.67.1
ffmpeg-private-devel-3.4.2-150200.11.67.1
libavcodec-devel-3.4.2-150200.11.67.1
libavcodec57-3.4.2-150200.11.67.1
libavcodec57-32bit-3.4.2-150200.11.67.1
libavdevice-devel-3.4.2-150200.11.67.1
libavdevice57-3.4.2-150200.11.67.1
libavdevice57-32bit-3.4.2-150200.11.67.1
libavfilter-devel-3.4.2-150200.11.67.1
libavfilter6-3.4.2-150200.11.67.1
libavfilter6-32bit-3.4.2-150200.11.67.1
libavformat-devel-3.4.2-150200.11.67.1
libavformat57-3.4.2-150200.11.67.1
libavformat57-32bit-3.4.2-150200.11.67.1
libavresample-devel-3.4.2-150200.11.67.1
libavresample3-3.4.2-150200.11.67.1
libavresample3-32bit-3.4.2-150200.11.67.1
libavutil-devel-3.4.2-150200.11.67.1
libavutil55-3.4.2-150200.11.67.1
libavutil55-32bit-3.4.2-150200.11.67.1
libpostproc-devel-3.4.2-150200.11.67.1
libpostproc54-3.4.2-150200.11.67.1
libpostproc54-32bit-3.4.2-150200.11.67.1
libswresample-devel-3.4.2-150200.11.67.1
libswresample2-3.4.2-150200.11.67.1
libswresample2-32bit-3.4.2-150200.11.67.1
libswscale-devel-3.4.2-150200.11.67.1
libswscale4-3.4.2-150200.11.67.1
libswscale4-32bit-3.4.2-150200.11.67.1
Ссылки
- Link for SUSE-SU-2025:02990-1
- E-Mail link for SUSE-SU-2025:02990-1
- SUSE Security Ratings
- SUSE Bug 1246790
- SUSE CVE CVE-2025-7700 page
Описание
A flaw was found in FFmpeg's ALS audio decoder, where it does not properly check for memory allocation failures. This can cause the application to crash when processing certain malformed audio files. While it does not lead to data theft or system control, it can be used to disrupt services and cause a denial of service.
Затронутые продукты
SUSE Linux Enterprise Module for Desktop Applications 15 SP6:libavcodec57-3.4.2-150200.11.67.1
SUSE Linux Enterprise Module for Desktop Applications 15 SP6:libavutil-devel-3.4.2-150200.11.67.1
SUSE Linux Enterprise Module for Desktop Applications 15 SP6:libavutil55-3.4.2-150200.11.67.1
SUSE Linux Enterprise Module for Desktop Applications 15 SP6:libpostproc-devel-3.4.2-150200.11.67.1
Ссылки
- CVE-2025-7700
- SUSE Bug 1246790