Release date:
Updated on:
Affected Systems:
FFmpeg
Description:
--------------------------------------------------------------------------------
FFmpeg is a free software that can execute video, transfer, and streaming media in multiple formats of audio and video, including libavcodec-this is a decoder library for audio and video in multiple projects, and libavformat-a library for converting audio and video formats.
FFmpeg has security vulnerabilities. Malicious users can exploit these vulnerabilities to cause denial of service and control applications that use affected databases.
1) An error occurs in the Sunplus JPEG decoder, which can be exploited by enticing users to open a specially crafted AMV file.
2) The "av_log_default_callback ()" function of libavutil/log. c has a race condition error.
<* Source: Dominic Chell
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
FFmpeg
------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://ffmpeg.sourceforge.net/