ALT-PU-2018-2593-1
Closed vulnerabilities
Published: 2018-08-24
BDU:2020-00758
Уязвимость функции flv_write_packet мультимедийной библиотеки FFmpeg, связанная с отсутствием проверки на наличие пустого аудиопакета, позволяющая нарушителю вызвать отказ в обслуживании
Severity: HIGH (7.5)
Vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
References:
Published: 2018-08-24
Modified: 2024-11-21
Modified: 2024-11-21
CVE-2018-15822
The flv_write_packet function in libavformat/flvenc.c in FFmpeg through 2.8 does not check for an empty audio packet, leading to an assertion failure.
Severity: HIGH (7.5)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
References:
- https://github.com/FFmpeg/FFmpeg/commit/6b67d7f05918f7a1ee8fc6ff21355d7e8736aa10
- https://github.com/FFmpeg/FFmpeg/commit/6b67d7f05918f7a1ee8fc6ff21355d7e8736aa10
- https://github.com/FFmpeg/FFmpeg/commit/d8ecb335fe4852bbc172c7b79e66944d158b4d92
- https://github.com/FFmpeg/FFmpeg/commit/d8ecb335fe4852bbc172c7b79e66944d158b4d92
- [debian-lts-announce] 20190529 [SECURITY] [DLA 1809-1] libav security update
- [debian-lts-announce] 20190529 [SECURITY] [DLA 1809-1] libav security update
- 20190523 [SECURITY] [DSA 4449-1] ffmpeg security update
- 20190523 [SECURITY] [DSA 4449-1] ffmpeg security update
- USN-3967-1
- USN-3967-1
- USN-4431-1
- USN-4431-1
- DSA-4449
- DSA-4449