First Last Prev Next    No search results available      Search page      Enter new bug
Bug#: 245313
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Stefan Behte <craig@gentoo.org>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 245313 depends on: 245285 Show dependency tree
Bug 245313 blocks:

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2008-11-02 19:43 0000
CVE-2008-4866 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-4866):
  Multiple buffer overflows in libavformat/utils.c in FFmpeg 0.4.9
  before r14715, as used by MPlayer, allow context-dependent attackers
  to have an unknown impact via vectors related to execution of DTS
  generation code with a delay greater than MAX_REORDER_DELAY.

------- Comment #1 From Stefan Behte 2008-11-02 19:47:37 0000 -------
Name:      CVE-2008-4867
URL:       http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4867
Published: 2008-10-31
Severity:
Description:

Buffer overflow in libavcodec/dca.c in FFmpeg 0.4.9 before r14917, as
used by MPlayer, allows context-dependent attackers to have an unknown
impact via vectors related to an incorrect DCA_MAX_FRAME_SIZE value.

Name:      CVE-2008-4868
URL:       http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4868
Published: 2008-10-31
Severity:
Description:

Unspecified vulnerability in the avcodec_close function in
libavcodec/utils.c in FFmpeg 0.4.9 before r14787, as used by MPlayer,
has unknown impact and attack vectors, related to a free "on random
pointers."

Name:      CVE-2008-4869
URL:       http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4869
Published: 2008-10-31
Severity:
Description:

FFmpeg 0.4.9, as used by MPlayer, allows context-dependent attackers to
cause a denial of service (memory consumption) via unknown vectors, aka
a "Tcp/udp memory leak."

------- Comment #2 From Stefan Behte 2008-11-02 19:55:11 0000 -------
CVE-2008-4867 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-4867):
  Buffer overflow in libavcodec/dca.c in FFmpeg 0.4.9 before r14917, as
  used by MPlayer, allows context-dependent attackers to have an
  unknown impact via vectors related to an incorrect DCA_MAX_FRAME_SIZE
  value.

CVE-2008-4868 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-4868):
  Unspecified vulnerability in the avcodec_close function in
  libavcodec/utils.c in FFmpeg 0.4.9 before r14787, as used by MPlayer,
  has unknown impact and attack vectors, related to a free "on random
  pointers."

CVE-2008-4869 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-4869):
  FFmpeg 0.4.9, as used by MPlayer, allows context-dependent attackers
  to cause a denial of service (memory consumption) via unknown
  vectors, aka a "Tcp/udp memory leak."

------- Comment #3 From Stefan Behte 2008-11-02 19:57:10 0000 -------
Sorry for the double-posting of the CVEs.

------- Comment #4 From Samuli Suominen 2008-12-13 22:43:54 0000 -------
Bug 245285 will close this, should Status Whiteboard be changed and arch teams
also be CC'd here?

------- Comment #5 From Samuli Suominen 2008-12-15 16:29:46 0000 -------
(In reply to comment #4)
> Bug 245285 will close this, should Status Whiteboard be changed and arch teams
> also be CC'd here?
> 

alpha (blackbird) and x86 (me) stable

------- Comment #6 From Ferris McCormick 2008-12-20 23:11:57 0000 -------
Sparc stable.

------- Comment #7 From nixnut 2008-12-21 14:35:22 0000 -------
ppc stable

------- Comment #8 From Raúl Porcel 2008-12-22 14:26:26 0000 -------
arm/ia64 stable

------- Comment #9 From Samuli Suominen 2008-12-22 14:37:49 0000 -------
Security: All archteams are done.

------- Comment #10 From Robert Buchholz 2008-12-23 12:37:16 0000 -------
glsa request filed

------- Comment #11 From Pierre-Yves Rofes 2009-03-20 08:31:57 0000 -------
GLSA 200903-33

First Last Prev Next    No search results available      Search page      Enter new bug