Updated ffmpeg packages fix security vulnerabilities
Publication date: 21 Nov 2014Modification date: 21 Nov 2014
Type: security
Affected Mageia releases : 4
CVE: CVE-2014-5271 , CVE-2014-5272 , CVE-2014-8541 , CVE-2014-8542 , CVE-2014-8543 , CVE-2014-8544 , CVE-2014-8545 , CVE-2014-8546 , CVE-2014-8547 , CVE-2014-8548
Description
A heap-based buffer overflow in the encode_slice function in libavcodec/proresenc_kostya.c in FFmpeg before 2.0.6 can cause a crash, allowing a malicious image file to cause a denial of service (CVE-2014-5271). libavcodec/iff.c in FFmpeg before 2.0.6 allows an attacker to have an unspecified impact via a crafted iff image, which triggers an out-of-bounds array access, related to the rgb8 and rgbn formats (CVE-2014-5272). libavcodec/mjpegdec.c in FFmpeg before 2.0.6 considers only dimension differences, and not bits-per-pixel differences, when determining whether an image size has changed, which allows remote attackers to cause a denial of service (out-of-bounds access) or possibly have unspecified other impact via crafted MJPEG data (CVE-2014-8541). libavcodec/utils.c in FFmpeg before 2.0.6 omits a certain codec ID during enforcement of alignment, which allows remote attackers to cause a denial of service (out-of-bounds access) or possibly have unspecified other impact via crafted JV data (CVE-2014-8542). libavcodec/mmvideo.c in FFmpeg before 2.0.6 does not consider all lines of HHV Intra blocks during validation of image height, which allows remote attackers to cause a denial of service (out-of-bounds access) or possibly have unspecified other impact via crafted MM video data (CVE-2014-8543). libavcodec/tiff.c in FFmpeg before 2.0.6 does not properly validate bits-per-pixel fields, which allows remote attackers to cause a denial of service (out-of-bounds access) or possibly have unspecified other impact via crafted TIFF data (CVE-2014-8544). libavcodec/pngdec.c in FFmpeg before 2.0.6 accepts the monochrome-black format without verifying that the bits-per-pixel value is 1, which allows remote attackers to cause a denial of service (out-of-bounds access) or possibly have unspecified other impact via crafted PNG data (CVE-2014-8545). Integer underflow in libavcodec/cinepak.c in FFmpeg before 2.0.6 allows remote attackers to cause a denial of service (out-of-bounds access) or possibly have unspecified other impact via crafted Cinepak video data (CVE-2014-8546). libavcodec/gifdec.c in FFmpeg before 2.0.6 does not properly compute image heights, which allows remote attackers to cause a denial of service (out-of-bounds access) or possibly have unspecified other impact via crafted GIF data (CVE-2014-8547). Off-by-one error in libavcodec/smc.c in FFmpeg before 2.0.6 allows remote attackers to cause a denial of service (out-of-bounds access) or possibly have unspecified other impact via crafted Quicktime Graphics (aka SMC) video data (CVE-2014-8548).
References
- https://bugs.mageia.org/show_bug.cgi?id=14042
- http://git.videolan.org/?p=ffmpeg.git;a=log;h=n2.0.6
- http://ffmpeg.org/olddownload.html
- http://ffmpeg.org/security.html
- http://openwall.com/lists/oss-security/2014/08/16/6
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-5271
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-5272
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8541
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8542
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8543
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8544
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8545
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8546
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8547
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8548
SRPMS
4/tainted
- ffmpeg-2.0.6-1.mga4.tainted
4/core
- ffmpeg-2.0.6-1.mga4