Multiple Remote Security Vulnerabilities in FFmpeg
Release date:
Updated on: 2012-04-10
Affected Systems:
FFmpeg 0.x
Description:
--------------------------------------------------------------------------------
FFmpeg is a free software that allows you to perform video, transfer, and stream functions in multiple formats of audio and video.
When FFmpeg parses some parameters, processes some action data, and decodes some proportional data, the function "srt_to_ass ()" (libavcodec/srtdec. c), "dirac_unpack_block_motion_data ()" (libavcodec/diracdec. c), "sws_init_context ()" (libswscale/utils. c) There are security vulnerabilities in implementation. Remote attackers can exploit these vulnerabilities to execute arbitrary code with current user permissions, resulting in DOS.
<* Source: Mateusz "j00ru" Jurczyk
Link: http://secunia.com/advisories/48770/
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
FFmpeg
------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://ffmpeg.sourceforge.net/