Skip to main content

FFmpeg Multiple Vulnerabilities

Last Update Date: 5 Mar 2013 16:01 Release Date: 5 Mar 2013 4404 Views

RISK: Medium Risk

TYPE: Clients - Audio & Video

TYPE: Audio & Video

Multiple vulnerabilities have been identified in FFmpeg, which can be exploited by malicious people to cause a DoS (Denial of Service) and potentially compromise an application using the library.

  1. An error within the "ff_h264_decode_seq_parameter_set()" function (libavcodec/h264_ps.c) when decoding certain parameter set can be exploited to cause an out of array access violation.
  2. An error within the "attribute_align_arg avcodec_decode_audio4()" function (libavcodec/utils.c) can be exploited to cause an out of array access violation.
  3. An error within the "swr_init()" function (libswresample/swresample.c) can be exploited to cause an out of array access violation.
  4. An error within the "read_header()" function (libavcodec/shorten.c) can be exploited to free invalid addresses.
  5. An error within the "doubles2str()" and "shorts2str()" functions (libavcodec/tiff.c) can be exploited to cause an out of array access violation.
  6. An error within the "ff_add_png_paeth_prediction()" function (libavcodec/pngdec.c) can be exploited to cause an out of array access violation.
  7. An integer overflow error within the "old_codec37()" function (libavcodec/sanm.c) can be exploited to corrupt memory. 
  8. An error within the "old_codec37()" function (libavcodec/sanm.c) can be exploited to cause an out of array access violation.
  9. An error within the "advance_line()" function (libavcodec/targa.c) can be exploited to cause an out of array access violation.

Impact

  • Denial of Service

System / Technologies affected

  • FFmpeg versions prior to 1.1.3.

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.

  • Update to version 1.1.3.

Vulnerability Identifier


Source


Related Link