FFmpeg 'libavcodec/vmdvideo. c' Denial of Service (CVE-2014-9603) Vulnerability)
Release date:
Updated on:
Affected Systems:
FFmpeg <2.5.2
Description:
Bugtraq id: 72269
CVE (CAN) ID: CVE-2014-9603
FFmpeg is a free software that allows you to perform video, transfer, and stream functions in multiple formats of audio and video.
For versions earlier than FFmpeg 2.5.2, libavcodec/vmdvideo. the function vmd_decode in c does not correctly verify the relationship between a specific length value and the secret width. This allows remote attackers to use the specially crafted sitlevmd video data, this vulnerability causes Denial of Service (out-of-bounds array access ).
<* Source: Mateusz "j00ru" Jurczyk
Gynvael Coldwind
*>
Suggestion:
Vendor patch:
FFmpeg
------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://git.videolan.org /? P = ffmpeg. git; a = commit; h = 3030fb7e0d41836f8add6399e9a7c7b740b48bfd
Compile FFmpeg in Linux to download and compile the source file
Linux compiling and upgrading FFmpeg
Install FFMPEG on CentOS 5.6
Install FFmpeg in Ubuntu
Compile ffmpeg in Ubuntu 12.04
Install FFmpeg 2.2.2 In PPA in Ubuntu 14.04
FFmpeg details: click here
FFmpeg: click here
This article permanently updates the link address: