Skip to main content

FFmpeg Multiple Vulnerabilities

Last Update Date: 17 Jun 2013 16:56 Release Date: 17 Jun 2013 3419 Views

RISK: Medium Risk

TYPE: Clients - Audio & Video

TYPE: Audio & Video

Multiple vulnerabilities have been identified in FFmpeg, which can be exploited by malicious people to cause a DoS (Denial of Service) and potentially compromise an application using the library.

  1. An error within the "format_line()" function (libavutil/log.c) can be exploited to dereference a certain pointer.
  2. An error within the "rle_unpack()" function (libavcodec/vmdav.c) can be exploited to cause an out of bounds memory access.
  3. An error within the "mm_decode_inter()" function (libavcodec/mmvideo.c) can be exploited to cause an out of bounds memory access.
  4. An integer overflow error within the "process_frame_obj()" function (libavcodec/sanm.c) can be exploited to cause an out of bounds memory access.
  5. An error within the "cdg_decode_frame()" function (libavcodec/cdgraphics.c) can be exploited to cause an out of bounds memory access.
  6. An error within the "gif_decode_frame()" function (libavcodec/gifdec.c) can be exploited to cause an out of bounds memory access.

Impact

  • Denial of Service
  • Remote Code Execution

System / Technologies affected

  • FFmpeg 1.x

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.

  • Update to version 1.2.1. 

Vulnerability Identifier


Source


Related Link