+++ This bug was initially created as a clone of Bug #339036 +++ From $url: The libavcodec library, an open source video encoding/decoding library part of the FFmpeg project, suffers from an arbitrary offset dereference vulnerability. The vulnerability affects the flic file format parser, insufficient restrictions on a writable buffer can be exploited to execute arbitrary code via the heap memory. A specific flic file can be crafted to trigger the vulnerability. The MPlayer multimedia player is also affected as it statically includes libavcodec, the flic codec can be disabled in codecs.conf configuration file in order to workaround the issue. The upstream fix is at: http://git.ffmpeg.org/?p=ffmpeg;a=commitdiff;h=16c592155f117ccd7b86006c45aacc692a81c23b
I think now we have a full release from upstream, see http://www.ffmpeg.org/releases/ffmpeg-0.6.1.release
The third party advisory at $URL lists: MPlayer >= snapshot 2010-09-28 as fixed. Our stable is more recent than this, so moving this to [glsa]
This issue was resolved and addressed in GLSA 201310-13 at http://security.gentoo.org/glsa/glsa-201310-13.xml by GLSA coordinator Sean Amoss (ackle).