FFmpeg Multiple Vulnerabilities
Last Update Date:
17 Jun 2013 16:56
Release Date:
17 Jun 2013
3957
Views
RISK: Medium Risk
TYPE: Clients - Audio & Video
Multiple vulnerabilities have been identified in FFmpeg, which can be exploited by malicious people to cause a DoS (Denial of Service) and potentially compromise an application using the library.
- An error within the "format_line()" function (libavutil/log.c) can be exploited to dereference a certain pointer.
- An error within the "rle_unpack()" function (libavcodec/vmdav.c) can be exploited to cause an out of bounds memory access.
- An error within the "mm_decode_inter()" function (libavcodec/mmvideo.c) can be exploited to cause an out of bounds memory access.
- An integer overflow error within the "process_frame_obj()" function (libavcodec/sanm.c) can be exploited to cause an out of bounds memory access.
- An error within the "cdg_decode_frame()" function (libavcodec/cdgraphics.c) can be exploited to cause an out of bounds memory access.
- An error within the "gif_decode_frame()" function (libavcodec/gifdec.c) can be exploited to cause an out of bounds memory access.
Impact
- Denial of Service
- Remote Code Execution
System / Technologies affected
- FFmpeg 1.x
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- Update to version 1.2.1.
Vulnerability Identifier
Source
Related Link
Share with