Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 781146 (CVE-2021-30123)

Summary: <media-video/ffmpeg-4.4: buffer overflow vulnerability in libavcodec (CVE-2021-30123)
Product: Gentoo Security Reporter: John Helmert III <ajak>
Component: VulnerabilitiesAssignee: Gentoo Security <security>
Status: IN_PROGRESS ---    
Severity: major CC: media-video
Priority: Normal Flags: nattka: sanity-check+
Version: unspecified   
Hardware: All   
OS: Linux   
URL: https://git.videolan.org/?p=ffmpeg.git;a=commitdiff;h=d6f293353c94c7ce200f6e0975ae3de49787f91f
Whiteboard: A2 [cleanup cve glsa+]
Package list:
media-video/ffmpeg-4.4
Runtime testing required: ---
Bug Depends on: 782412, 790590    
Bug Blocks:    

Description John Helmert III gentoo-dev Security 2021-04-08 14:45:31 UTC
CVE-2021-30123:

FFmpeg <=4.3 contains a buffer overflow vulnerability in libavcodec through a crafted file that may lead to remote code execution.


Patch at $URL but seems it's not part of any tag yet.
Comment 1 jospezial 2021-04-09 11:59:28 UTC
It is in just released 4.4 .
Comment 3 John Helmert III gentoo-dev Security 2021-04-09 14:17:22 UTC
(In reply to jospezial from comment #1)
> It is in just released 4.4 .

Thanks! Maintainers, please bump.
Comment 4 jospezial 2021-04-09 21:44:24 UTC
https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=ddb6d10608a9396bb123add897b15fe01538ce68
media-video/ffmpeg: bump to 4.4
Comment 5 Sam James archtester gentoo-dev Security 2021-04-09 22:06:46 UTC
(In reply to jospezial from comment #4)
> https://gitweb.gentoo.org/repo/gentoo.git/commit/
> ?id=ddb6d10608a9396bb123add897b15fe01538ce68
> media-video/ffmpeg: bump to 4.4

Thanks!
Comment 6 Agostino Sarubbo gentoo-dev 2021-05-12 07:58:39 UTC
amd64 stable
Comment 7 Agostino Sarubbo gentoo-dev 2021-05-12 20:12:37 UTC
x86 stable
Comment 8 Agostino Sarubbo gentoo-dev 2021-05-14 06:42:48 UTC
ppc64 stable
Comment 9 Sam James archtester gentoo-dev Security 2021-05-15 18:00:03 UTC
arm64 done
Comment 10 Sam James archtester gentoo-dev Security 2021-05-15 18:02:17 UTC
arm done
Comment 11 Sam James archtester gentoo-dev Security 2021-05-16 12:46:01 UTC
sparc done
Comment 12 Thomas Deutschmann gentoo-dev Security 2021-05-24 00:03:33 UTC
New GLSA request filed.
Comment 13 GLSAMaker/CVETool Bot gentoo-dev 2021-05-26 09:50:50 UTC
This issue was resolved and addressed in
 GLSA 202105-24 at https://security.gentoo.org/glsa/202105-24
by GLSA coordinator Thomas Deutschmann (whissi).
Comment 14 Thomas Deutschmann gentoo-dev Security 2021-05-26 09:51:29 UTC
Re-opening for remaining architecture.
Comment 15 John Helmert III gentoo-dev Security 2021-05-30 16:20:12 UTC
Ping ppc
Comment 16 Sergei Trofimovich gentoo-dev 2021-06-07 07:41:54 UTC
ppc stable

All arches done.
Comment 17 John Helmert III gentoo-dev Security 2021-06-09 04:29:33 UTC
Please cleanup.