Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 626360 (CVE-2017-11665) - <media-video/ffmpeg-3.3.3: denial of service via a crafted stream (CVE-2017-11665)
Summary: <media-video/ffmpeg-3.3.3: denial of service via a crafted stream (CVE-2017-1...
Status: RESOLVED FIXED
Alias: CVE-2017-11665
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Gentoo Security
URL:
Whiteboard: B3 [noglsa cve]
Keywords:
Depends on: CVE-2017-11399
Blocks:
  Show dependency tree
 
Reported: 2017-07-27 13:47 UTC by Aleksandr Wagner (Kivak)
Modified: 2017-10-26 00:39 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Aleksandr Wagner (Kivak) 2017-07-27 13:47:38 UTC
CVE-2017-11665 (http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-11665):

The ff_amf_get_field_value function in libavformat/rtmppkt.c in FFmpeg 3.3.2 allows remote RTMP servers to cause a denial of service (Segmentation Violation and application crash) via a crafted stream. 

Reference:

https://gist.github.com/singleghost/7d94dda50856e707e1c92d068bbc244e
Comment 1 Alexis Ballier gentoo-dev 2017-07-30 14:28:13 UTC
that gist is a 404
Comment 2 Christopher Díaz Riveros (RETIRED) gentoo-dev Security 2017-07-30 15:01:21 UTC
This is the commit where that issue is fixed

https://git.ffmpeg.org/gitweb/ffmpeg.git/commit/ffcc82219cef0928bed2d558b19ef6ea35634130

ChrisADR
Security Project Padawan
Comment 3 Alexis Ballier gentoo-dev 2017-07-30 15:32:20 UTC
ok, so 3.3.3 has the fix and we can track stabilization in bug #626414
Comment 4 Aaron Bauman (RETIRED) gentoo-dev 2017-10-26 00:39:04 UTC
GLSA Vote: No

Cleanup handled in bug #630460