FFmpeg 'libavcodec/utvideodec. c' Denial of Service Vulnerability (CVE-2014-9604)
FFmpeg 'libavcodec/utvideodec. c' Denial of Service Vulnerability (CVE-2014-9604)
Release date:
Updated on:
Affected Systems:
FFmpeg <2.5.2
Description:
Bugtraq id: 72272
CVE (CAN) ID: CVE-2014-9604
FFmpeg is a free software that allows you to perform video, transfer, and stream functions in multiple formats of audio and video.
For versions earlier than FFmpeg 2.5.2, libavcodec/utvideodec. c does not check the zero value of the clip height, which allows remote attackers to exploit this vulnerability to cause Denial-of-Service (out-of-bounds array access) by specially crafted Ut Video data ).
<* Source: Mateusz "j00ru" Jurczyk
Gynvael Coldwind
*>
Suggestion:
Vendor patch:
FFmpeg
------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://git.videolan.org /? P = ffmpeg. git; a = commit; h = 3881606240953b9275a247a1c98a567f3c44890f
Compile FFmpeg in Linux to download and compile the source file
Linux compiling and upgrading FFmpeg
Install FFMPEG on CentOS 5.6
Install FFmpeg in Ubuntu
Compile ffmpeg in Ubuntu 12.04
Install FFmpeg 2.2.2 In PPA in Ubuntu 14.04
FFmpeg details: click here
FFmpeg: click here
This article permanently updates the link address: