ALT-PU-2018-1929-2
Closed vulnerabilities
BDU:2024-09050
Уязвимость функции export компонента libavfilter/vf_signature.c мультимедийной библиотеки FFmpeg, связанная с чтением за допустимыми границами буфера данных, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании
BDU:2024-09051
Уязвимость функции svg_probe компонента libavformat/img2dec.c мультимедийной библиотеки FFmpeg, связанная с выполнением цикла с недоступным условием выхода, позволяющая нарушителю вызвать отказ в обслуживании
BDU:2024-09052
Уязвимость функции decode_plane компонента libavcodec/utvideodec.c мультимедийной библиотеки FFmpeg, связанная с чтением за допустимыми границами буфера данных, позволяющая нарушителю вызвать отказ в обслуживании
BDU:2024-09059
Уязвимость протокола mms мультимедийной библиотеки FFmpeg, связанная с чтением за допустимыми границами буфера данных, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании
Modified: 2024-11-21
CVE-2018-10001
The decode_init function in libavcodec/utvideodec.c in FFmpeg through 3.4.2 allows remote attackers to cause a denial of service (out of array read) via an AVI file.
- http://git.videolan.org/?p=ffmpeg.git%3Ba=commit%3Bh=47b7c68ae54560e2308bdb6be4fb076c73b93081
- http://www.securityfocus.com/bid/103732
- https://security.gentoo.org/glsa/202003-65
- https://www.debian.org/security/2018/dsa-4249
- http://git.videolan.org/?p=ffmpeg.git%3Ba=commit%3Bh=47b7c68ae54560e2308bdb6be4fb076c73b93081
- http://www.securityfocus.com/bid/103732
- https://security.gentoo.org/glsa/202003-65
- https://www.debian.org/security/2018/dsa-4249
Modified: 2024-11-21
CVE-2018-1999010
FFmpeg before commit cced03dd667a5df6df8fd40d8de0bff477ee02e8 contains multiple out of array access vulnerabilities in the mms protocol that can result in attackers accessing out of bound data. This attack appear to be exploitable via network connectivity. This vulnerability appears to have been fixed in cced03dd667a5df6df8fd40d8de0bff477ee02e8 and later.
- http://www.securityfocus.com/bid/104896
- https://github.com/FFmpeg/FFmpeg/commit/cced03dd667a5df6df8fd40d8de0bff477ee02e8
- https://lists.debian.org/debian-lts-announce/2019/01/msg00006.html
- http://www.securityfocus.com/bid/104896
- https://github.com/FFmpeg/FFmpeg/commit/cced03dd667a5df6df8fd40d8de0bff477ee02e8
- https://lists.debian.org/debian-lts-announce/2019/01/msg00006.html
Modified: 2024-11-21
CVE-2018-6392
The filter_slice function in libavfilter/vf_transpose.c in FFmpeg through 3.4.1 allows remote attackers to cause a denial of service (out-of-array access) via a crafted MP4 file.
- http://www.securityfocus.com/bid/102848
- https://git.ffmpeg.org/gitweb/ffmpeg.git/commit/3f621455d62e46745453568d915badd5b1e5bcd5
- https://git.ffmpeg.org/gitweb/ffmpeg.git/commit/c6939f65a116b1ffed345d29d8621ee4ffb32235
- https://lists.debian.org/debian-lts-announce/2019/03/msg00041.html
- https://www.debian.org/security/2018/dsa-4249
- http://www.securityfocus.com/bid/102848
- https://git.ffmpeg.org/gitweb/ffmpeg.git/commit/3f621455d62e46745453568d915badd5b1e5bcd5
- https://git.ffmpeg.org/gitweb/ffmpeg.git/commit/c6939f65a116b1ffed345d29d8621ee4ffb32235
- https://lists.debian.org/debian-lts-announce/2019/03/msg00041.html
- https://www.debian.org/security/2018/dsa-4249
Modified: 2024-11-21
CVE-2018-6912
The decode_plane function in libavcodec/utvideodec.c in FFmpeg through 3.4.2 allows remote attackers to cause a denial of service (out of array read) via a crafted AVI file.
Modified: 2024-11-21
CVE-2018-7557
The decode_init function in libavcodec/utvideodec.c in FFmpeg 2.8 through 3.4.2 allows remote attackers to cause a denial of service (Out of array read) via an AVI file with crafted dimensions within chroma subsampling data.
- https://git.ffmpeg.org/gitweb/ffmpeg.git/commit/7414d0bda7763f9bd69c26c068e482ab297c1c96
- https://github.com/FFmpeg/FFmpeg/commit/e724bd1dd9efea3abb8586d6644ec07694afceae
- https://lists.debian.org/debian-lts-announce/2019/01/msg00006.html
- https://security.gentoo.org/glsa/202003-65
- https://www.debian.org/security/2018/dsa-4249
- https://git.ffmpeg.org/gitweb/ffmpeg.git/commit/7414d0bda7763f9bd69c26c068e482ab297c1c96
- https://github.com/FFmpeg/FFmpeg/commit/e724bd1dd9efea3abb8586d6644ec07694afceae
- https://lists.debian.org/debian-lts-announce/2019/01/msg00006.html
- https://security.gentoo.org/glsa/202003-65
- https://www.debian.org/security/2018/dsa-4249
Modified: 2024-11-21
CVE-2018-7751
The svg_probe function in libavformat/img2dec.c in FFmpeg through 3.4.2 allows remote attackers to cause a denial of service (Infinite Loop) via a crafted XML file.
- http://www.securityfocus.com/bid/103956
- https://git.ffmpeg.org/gitweb/ffmpeg.git/commit/a6cba062051f345e8ebfdff34aba071ed73d923f
- https://security.gentoo.org/glsa/202003-65
- http://www.securityfocus.com/bid/103956
- https://git.ffmpeg.org/gitweb/ffmpeg.git/commit/a6cba062051f345e8ebfdff34aba071ed73d923f
- https://security.gentoo.org/glsa/202003-65
Modified: 2024-11-21
CVE-2018-9841
The export function in libavfilter/vf_signature.c in FFmpeg through 3.4.2 allows remote attackers to cause a denial of service (out-of-array access) or possibly have unspecified other impact via a long filename.
