Release date: 2011-11-21
Updated on: 2011-11-23
Affected Systems:
FFmpeg 0.x
Unaffected system:
FFmpeg 0.8.7
FFmpeg 0.7.8
Description:
--------------------------------------------------------------------------------
Bugtraq id: 50760
FFmpeg is a free software that allows you to perform video, transfer, and stream functions in multiple formats of audio and video.
FFmpeg versions earlier than 0.7.8 and 0.8.7 have multiple remote code execution vulnerabilities. Remote attackers can exploit these vulnerabilities to cause denial-of-service attacks and control applications that use affected libraries.
1) An error in the QDM2 Decoder (libavcodec/qdm2.c) can cause a buffer overflow;
2) integer overflow errors in the "vp3_dequant ()" function (libavcodec/vp3.c) can cause buffer overflow;
3) errors in "av_image_fill_pointers ()", "vp5_parse_coeff ()", and "vp6_parse_coeff ()" can trigger cross-border read.
<* Source: vendor
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
FFmpeg
------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://ffmpeg.sourceforge.net/