Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 401069 (CVE-2011-3929) - <media-video/ffmpeg-0.10.2 : Multiple vulnerabilities (CVE-2011-{3929,3934,3935,3936,3937,3940,3941,3944,3945,3946,3947,3949,3950,3951,3952})
Summary: <media-video/ffmpeg-0.10.2 : Multiple vulnerabilities (CVE-2011-{3929,3934,39...
Status: RESOLVED FIXED
Alias: CVE-2011-3929
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Gentoo Security
URL: http://ffmpeg.org/index.html#pr10
Whiteboard: B2 [glsa]
Keywords:
Depends on: 392269 ffmpeg-0.10 411369
Blocks:
  Show dependency tree
 
Reported: 2012-01-27 19:48 UTC by Hanno Böck
Modified: 2013-12-12 14:50 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Hanno Böck gentoo-dev 2012-01-27 19:48:43 UTC
See
http://ffmpeg.org/index.html#pr10

Please bump to ffmpeg-0.10.
Comment 1 Alexis Ballier gentoo-dev 2012-01-28 12:51:45 UTC
in cvs
Comment 2 Tim Sammut (RETIRED) gentoo-dev 2012-01-28 17:01:38 UTC
Are we anywhere near being able to stabilize this? Or 0.9? Thanks.
Comment 3 Alexis Ballier gentoo-dev 2012-02-01 14:33:44 UTC
(In reply to comment #2)
> Are we anywhere near being able to stabilize this? Or 0.9? Thanks.

now that transcode is fixed, go for 0.10
Comment 4 Tim Sammut (RETIRED) gentoo-dev 2012-02-02 02:38:25 UTC
(In reply to comment #3)
> 
> now that transcode is fixed, go for 0.10

Once keywording is complete in bug 392269 are we ready move forward to stabilize 0.10?
Comment 5 Alexis Ballier gentoo-dev 2012-02-02 14:19:51 UTC
(In reply to comment #4)
> (In reply to comment #3)
> > 
> > now that transcode is fixed, go for 0.10
> 
> Once keywording is complete in bug 392269 are we ready move forward to
> stabilize 0.10?

the same as for 0.9: once someone has checked the reverse deps, yes
Comment 6 Alexis Ballier gentoo-dev 2012-02-23 13:24:15 UTC
CCing arches.

We have a completely bloated, security-wide, mplayer, with almost one year of issues accumulated. Stable ffmpeg (and libav btw) is affected by the issues mentionned in this bug.

Arches, please check your stable reverse deps, and if something fails, add them as blockers to bug #395379 . Otherwise proceed to ffmpeg-0.10 stabilisation.


Note that almost every single video player on *nix uses ffmpeg, and those are usually fed with untrusted files, so I feel a bit ashamed to be that late in providing safe libraries considering the large impact it has.
Comment 7 Agostino Sarubbo gentoo-dev 2012-02-23 13:53:44 UTC
@sound, jfyi, libaacplus is pulled in and it will be stabilized
Comment 8 Agostino Sarubbo gentoo-dev 2012-02-23 13:56:56 UTC
(In reply to comment #6)
> Arches, please check your stable reverse deps, and if something fails, add them
> as blockers to bug #395379 . Otherwise proceed to ffmpeg-0.10 stabilisation.

sure, but can you provide a stable list with packages needs testing?
Comment 9 Alexis Ballier gentoo-dev 2012-02-23 14:04:08 UTC
(In reply to comment #7)
> @sound, jfyi, libaacplus is pulled in and it will be stabilized

fine by me

(In reply to comment #8)
> (In reply to comment #6)
> > Arches, please check your stable reverse deps, and if something fails, add them
> > as blockers to bug #395379 . Otherwise proceed to ffmpeg-0.10 stabilisation.
> 
> sure, but can you provide a stable list with packages needs testing?

 ( http://tinderbox.dev.gentoo.org/misc/rindex/media-video/ffmpeghttp://tinderbox.dev.gentoo.org/misc/rindex/virtual/ffmpeg ) ∩ { stable packages }

:=)

i remember there's a tool lying around to get stable rev deps but i dont remember more :(

we've asked for tinderbox runs, but noone was willing to do it (see bug #389037 and bug #394809 comment 4 ), so here we are...
Comment 10 Alexis Ballier gentoo-dev 2012-02-23 21:14:51 UTC
(In reply to comment #9)
>  ( http://tinderbox.dev.gentoo.org/misc/rindex/media-video/ffmpeg ∪
> http://tinderbox.dev.gentoo.org/misc/rindex/virtual/ffmpeg ) ∩ { stable
> packages }
> 
> :=)
> 
> i remember there's a tool lying around to get stable rev deps but i dont
> remember more :(

http://phajdan-jr.blogspot.com/2011/10/exhaustive-testing-of-stable-reverse.html
Comment 11 Agostino Sarubbo gentoo-dev 2012-02-25 13:16:14 UTC
(In reply to comment #6)
> Arches, please check your stable reverse deps, and if something fails, add them
> as blockers to bug #395379 . Otherwise proceed to ffmpeg-0.10 stabilisation.

Done



Removing arches until all bugs will be fixed.
Comment 12 Alexis Ballier gentoo-dev 2012-02-25 23:41:21 UTC
(In reply to comment #11)
> (In reply to comment #6)
> > Arches, please check your stable reverse deps, and if something fails, add them
> > as blockers to bug #395379 . Otherwise proceed to ffmpeg-0.10 stabilisation.
> 
> Done

thanks a lot !

(In reply to comment #11)
> Removing arches until all bugs will be fixed.

but please readd arches that are not affected by these bugs and may want to fix these sec. holes...
Comment 13 Alexis Ballier gentoo-dev 2012-03-11 13:58:54 UTC
(In reply to comment #12)
> (In reply to comment #11)
> > Removing arches until all bugs will be fixed.
> 
> but please readd arches that are not affected by these bugs and may want to
> fix these sec. holes...

thank you...


you have all the stable request filled now, as blocking this bug, so you can proceed
Comment 14 Jeroen Roovers (RETIRED) gentoo-dev 2012-03-25 17:03:54 UTC
Stable for HPPA.
Comment 15 Brent Baude (RETIRED) gentoo-dev 2012-03-28 20:20:04 UTC
ppc64 done
Comment 16 Agostino Sarubbo gentoo-dev 2012-03-29 10:58:14 UTC
x264 is pulled in, what version we should stabilize?
Comment 17 Alexis Ballier gentoo-dev 2012-03-30 20:08:59 UTC
(In reply to comment #16)
> x264 is pulled in, what version we should stabilize?

media-libs/x264-0.0.20111220 AND media-video/x264-encoder-0.0.20111220
Comment 18 Agostino Sarubbo gentoo-dev 2012-03-31 14:57:31 UTC
ffmpegsource is pulled in and fails to compile
Comment 19 Alexis Ballier gentoo-dev 2012-04-08 14:44:25 UTC
(In reply to comment #18)
> ffmpegsource is pulled in and fails to compile

use.masked on all but latest versions
Comment 20 Agostino Sarubbo gentoo-dev 2012-04-09 15:59:02 UTC
amd64 stable
Comment 21 Agostino Sarubbo gentoo-dev 2012-04-09 19:33:37 UTC
Other arches will continue in bug 411369
Comment 22 Sean Amoss (RETIRED) gentoo-dev Security 2012-05-13 23:09:05 UTC
Thanks, everyone. Added to existing GLSA request.
Comment 23 Alexis Ballier gentoo-dev 2013-08-14 21:15:23 UTC
nothing left to do for media-video@
Comment 24 GLSAMaker/CVETool Bot gentoo-dev 2013-10-25 19:11:45 UTC
This issue was resolved and addressed in
 GLSA 201310-12 at http://security.gentoo.org/glsa/glsa-201310-12.xml
by GLSA coordinator Sean Amoss (ackle).
Comment 25 GLSAMaker/CVETool Bot gentoo-dev 2013-12-12 14:50:21 UTC
CVE-2011-3950 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-3950):
  The dirac_decode_data_unit function in libavcodec/diracdec.c in FFmpeg
  before 0.10 allows remote attackers to have an unspecified impact via a
  crafted value in the reference pictures number.

CVE-2011-3949 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-3949):
  The dirac_unpack_idwt_params function in libavcodec/diracdec.c in FFmpeg
  before 0.10 allows remote attackers to have an unspecified impact via
  crafted Dirac data.

CVE-2011-3946 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-3946):
  The ff_h264_decode_sei function in libavcodec/h264_sei.c in FFmpeg before
  0.10 allows remote attackers to have an unspecified impact via crafted
  Supplemental enhancement information (SEI) data, which triggers an infinite
  loop.

CVE-2011-3944 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-3944):
  The smacker_decode_header_tree function in libavcodec/smacker.c in FFmpeg
  before 0.10 allows remote attackers to have an unspecified impact via
  crafted Smacker data.

CVE-2011-3941 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-3941):
  The decode_mb function in libavcodec/error_resilience.c in FFmpeg before
  0.10 allows remote attackers to have an unspecified impact via vectors
  related to an uninitialized block index, which triggers an out-of-bound
  write.

CVE-2011-3935 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-3935):
  The codec_get_buffer function in ffmpeg.c in FFmpeg before 0.10 allows
  remote attackers to have an unspecified impact via vectors related to a
  crafted image size.

CVE-2011-3934 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-3934):
  Double free vulnerability in the vp3_update_thread_context function in
  libavcodec/vp3.c in FFmpeg before 0.10 allows remote attackers to have an
  unspecified impact via crafted vp3 data.