Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 391421 (CVE-2011-4351) - <media-video/ffmpeg-0.7.8 multiple vulnerabilities (CVE-2011-{4351,4352,4353})
Summary: <media-video/ffmpeg-0.7.8 multiple vulnerabilities (CVE-2011-{4351,4352,4353})
Status: RESOLVED FIXED
Alias: CVE-2011-4351
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Gentoo Security
URL: http://ffmpeg.org/#pr7dot8and8dot7
Whiteboard: B2 [glsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2011-11-22 19:04 UTC by Sean Amoss (RETIRED)
Modified: 2013-10-25 19:11 UTC (History)
0 users

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Sean Amoss (RETIRED) gentoo-dev Security 2011-11-22 19:04:30 UTC
FFmpeg reports 0.7.8 and 0.8.7 fix multiple security bugs at $URL.

Secunia advisory states:

"Some vulnerabilities have been reported in FFmpeg, which can be exploited by malicious people to cause a DoS (Denial of Service) and potentially compromise an application using the library.

1) An error within the QDM2 decoder (libavcodec/qdm2.c) can be exploited to cause a buffer overflow.

2) An integer overflow error within the "vp3_dequant()" function (libavcodec/vp3.c) can be exploited to cause a buffer overflow.

3) Errors within the "av_image_fill_pointers()", the "vp5_parse_coeff()", and the "vp6_parse_coeff()" functions can be exploited to trigger out-of-bounds reads.

The vulnerabilities are reported in versions prior to 0.7.8 and 0.8.7."
Comment 1 Alexis Ballier gentoo-dev 2011-11-23 21:28:35 UTC
0.7.8 is in the tree now
Comment 2 Sean Amoss (RETIRED) gentoo-dev Security 2011-11-26 10:48:25 UTC
Thanks. Is =media-video/ffmpeg-0.7.8 ready for stabilization?
Comment 3 Agostino Sarubbo gentoo-dev 2011-11-27 11:02:43 UTC
(In reply to comment #2)
> Thanks. Is =media-video/ffmpeg-0.7.8 ready for stabilization?

Yes, as usually =)

Arches, please test and mark stable:                                                                                                                                                
=media-video/ffmpeg-0.7.8                                                                                                                                                           
Target keywords : "alpha amd64 arm hppa ia64 ppc ppc64 sparc x86"
Comment 4 Agostino Sarubbo gentoo-dev 2011-11-27 11:12:53 UTC
amd64 ok

@aballier, I guess that x11-libs/libXfixes is missing as RDEP.
Comment 5 Elijah "Armageddon" El Lazkani (amd64 AT) 2011-11-27 21:35:40 UTC
amd64: pass
Comment 6 Tony Vroon (RETIRED) gentoo-dev 2011-11-28 22:55:49 UTC
+  28 Nov 2011; Tony Vroon <chainsaw@gentoo.org> ffmpeg-0.7.8.ebuild:
+  Marked stable on AMD64 based on arch testing by Agostino "ago" Sarubbo &
+  Elijah "Armageddon" El Lazkani in security bug #391421.
Comment 7 Jeroen Roovers (RETIRED) gentoo-dev 2011-11-29 23:21:33 UTC
Stable for HPPA.
Comment 8 Paweł Hajdan, Jr. (RETIRED) gentoo-dev 2011-12-01 19:57:50 UTC
x86 stable
Comment 9 Raúl Porcel (RETIRED) gentoo-dev 2011-12-03 17:17:23 UTC
alpha/arm/ia64/sh/sparc stable
Comment 10 Mark Loeser (RETIRED) gentoo-dev 2011-12-18 22:11:04 UTC
ppc/ppc64 done
Comment 11 Tim Sammut (RETIRED) gentoo-dev 2011-12-18 22:14:04 UTC
Thanks folks. Added to existing GLSA request.
Comment 12 GLSAMaker/CVETool Bot gentoo-dev 2012-08-24 22:01:34 UTC
CVE-2011-4353 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-4353):
  The (1) av_image_fill_pointers, (2) vp5_parse_coeff, and (3) vp6_parse_coeff
  functions in FFmpeg 0.5.x before 0.5.7, 0.6.x before 0.6.4, 0.7.x before
  0.7.9, and 0.8.x before 0.8.8; and in Libav 0.5.x before 0.5.6, 0.6.x before
  0.6.4, and 0.7.x before 0.7.3 allow remote attackers to cause a denial of
  service (out-of-bounds read) via a crafted VP5 or VP6 stream.

CVE-2011-4352 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-4352):
  Integer overflow in the vp3_dequant function in the VP3 decoder (vp3.c) in
  libavcodec in FFmpeg 0.5.x before 0.5.7, 0.6.x before 0.6.4, 0.7.x before
  0.7.9, and 0.8.x before 0.8.8; and in Libav 0.5.x before 0.5.6, 0.6.x before
  0.6.4, and 0.7.x before 0.7.3 allows remote attackers to cause a denial of
  service (crash) and possibly execute arbitrary code via a crafted VP3
  stream, which triggers a buffer overflow.
Comment 13 Alexis Ballier gentoo-dev 2013-08-14 21:14:43 UTC
nothing left to do for media-video@
Comment 14 GLSAMaker/CVETool Bot gentoo-dev 2013-10-25 19:11:40 UTC
This issue was resolved and addressed in
 GLSA 201310-12 at http://security.gentoo.org/glsa/glsa-201310-12.xml
by GLSA coordinator Sean Amoss (ackle).