FFmpeg and Libav cross-border Denial of Service Vulnerability (CVE-2014-8545)
Release date: 2014-3 3
Updated on:
Affected Systems:
FFmpeg <2.4.2
FFmpeg
Description:
Bugtraq id: 70886
CVE (CAN) ID: CVE-2014-8545
FFmpeg is a free software that allows you to perform video, transfer, and stream functions in multiple formats of audio and video. Libav is a cross-platform free software that allows you to perform video, transfer, and stream functions in multimedia formats and protocols.
FFmpeg and Libav have a Denial-of-Service vulnerability. Attackers can exploit this vulnerability to cause application crashes in the affected database and cause denial of service to legitimate users.
<* Source: Mateusz "j00ru" Jurczyk
Gynvael Coldwind
*>
Suggestion:
Vendor patch:
FFmpeg
------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Https://www.ffmpeg.org/security.html
Compile FFmpeg in Linux to download and compile the source file
Linux compiling and upgrading FFmpeg
Install FFMPEG on CentOS 5.6
Install FFmpeg 2.4 In Ubuntu, a multimedia processing tool
FFmpeg details: click here
FFmpeg: click here
This article permanently updates the link address: