Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 382301 - <media-video/ffmpeg-0.7.4: Multiple vulnerabilities (CVE-2010-{3908,4704},CVE-2011-{1931,3973,3974})
Summary: <media-video/ffmpeg-0.7.4: Multiple vulnerabilities (CVE-2010-{3908,4704},CVE...
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Gentoo Security
URL:
Whiteboard: B2 [glsa]
Keywords:
Depends on: 384095
Blocks:
  Show dependency tree
 
Reported: 2011-09-08 18:09 UTC by Alexis Ballier
Modified: 2013-10-25 19:11 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Alexis Ballier gentoo-dev 2011-09-08 18:09:16 UTC
commit c2a2ad133eb9d42361804a568dee336992349a5e
Author: Michael Niedermayer <michaelni@gmx.at>
Date:   Wed Sep 7 14:12:42 2011 +0200

    rtp: Fix integer underflow that could allow remote code execution.
    
    Fixes MSVR-11-0088
    Credit:  Jeong Wook Oh of Microsoft and Microsoft Vulnerability Research (MSVR)
    Signed-off-by: Michael Niedermayer <michaelni@gmx.at>
 

commit cb8577a4dac816f264da294ee354311899b10032
Author: Michael Niedermayer <michaelni@gmx.at>
Date:   Thu Jul 28 14:59:54 2011 +0200

    Fix several security issues in matroskadec.c (MSVR-11-0080).
    
    Whitespace of the patch cleaned up by Aurel
    Some of the issues have been reported by Steve Manzuik / Microsoft Vulnerability Research (MSVR)
    Signed-off-by: Michael Niedermayer <michaelni@gmx.at>

commit 7e33a66c0e178c3576c1ba1648be4295809adca8
Author: Michael Niedermayer <michaelni@gmx.at>
Date:   Thu Jul 28 14:59:54 2011 +0200

    Fix several security issues in matroskadec.c (MSVR-11-0080).
    
    Whitespace of the patch cleaned up by Aurel
    Some of the issues have been reported by Steve Manzuik / Microsoft Vulnerability Research (MSVR)
    Signed-off-by: Michael Niedermayer <michaelni@gmx.at>



good for a quick stabilisation imho
Comment 1 Tim Sammut (RETIRED) gentoo-dev 2011-09-08 19:51:33 UTC
Great, thank you.

Arches, please test and mark stable:
=media-video/ffmpeg-0.7.4
Target keywords : "alpha amd64 arm hppa ia64 ppc ppc64 sparc x86"
Comment 2 Jeff (JD) Horelick (RETIRED) gentoo-dev 2011-09-08 22:40:46 UTC
Archtested on x86: Everything seems fine
Comment 3 Agostino Sarubbo gentoo-dev 2011-09-08 23:41:22 UTC
amd64 ok
Comment 4 Elijah "Armageddon" El Lazkani (amd64 AT) 2011-09-09 02:55:52 UTC
amd64: pass
Comment 5 Tomáš "tpruzina" Pružina (amd64 [ex]AT) 2011-09-09 07:21:13 UTC
amd64 ok
Comment 6 Jeroen Roovers (RETIRED) gentoo-dev 2011-09-10 17:55:21 UTC
Stable for HPPA.
Comment 7 Markus Meier gentoo-dev 2011-09-11 21:24:23 UTC
x86 stable, thanks JD
Comment 8 Markus Meier gentoo-dev 2011-09-12 21:10:36 UTC
arm stable
Comment 9 Markos Chandras (RETIRED) gentoo-dev 2011-09-13 09:52:30 UTC
amd64 done. Thank you all
Comment 10 Raúl Porcel (RETIRED) gentoo-dev 2011-09-17 16:49:07 UTC
alpha/ia64/sparc stable
Comment 11 Tim Sammut (RETIRED) gentoo-dev 2011-09-22 16:40:24 UTC
There is a newer version to stabilize via bug 384095.
Comment 12 Tim Sammut (RETIRED) gentoo-dev 2011-10-02 14:28:01 UTC
Rerating B2, and added to existing GLSA request now that stabilization in 384095 has completed. Thanks, folks.
Comment 13 GLSAMaker/CVETool Bot gentoo-dev 2011-10-07 23:33:32 UTC
CVE-2011-3974 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-3974):
  Integer signedness error in the decode_residual_inter function in cavsdec.c
  in libavcodec in FFmpeg before 0.7.4 and 0.8.x before 0.8.3 allows remote
  attackers to cause a denial of service (incorrect write operation and
  application crash) via an invalid bitstream in a Chinese AVS video (aka
  CAVS) file, a different vulnerability than CVE-2011-3362.
Comment 14 GLSAMaker/CVETool Bot gentoo-dev 2011-10-07 23:35:48 UTC
CVE-2011-3973 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-3973):
  cavsdec.c in libavcodec in FFmpeg before 0.7.4 and 0.8.x before 0.8.3 allows
  remote attackers to cause a denial of service (incorrect write operation and
  application crash) via an invalid bitstream in a Chinese AVS video (aka
  CAVS) file, related to the decode_residual_block, check_for_slice, and
  cavs_decode_frame functions, a different vulnerability than CVE-2011-3362.
Comment 15 GLSAMaker/CVETool Bot gentoo-dev 2011-10-07 23:39:44 UTC
CVE-2011-1931 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-1931):
  sp5xdec.c in the Sunplus SP5X JPEG decoder in libavcodec in FFmpeg before
  0.6.3 and libav through 0.6.2, as used in VideoLAN VLC media player 1.1.9
  and earlier and other products, performs a write operation outside the
  bounds of an unspecified array, which allows remote attackers to cause a
  denial of service (memory corruption) or possibly execute arbitrary code via
  a malformed AMV file.
Comment 16 GLSAMaker/CVETool Bot gentoo-dev 2011-10-07 23:46:13 UTC
CVE-2010-4704 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-4704):
  libavcodec/vorbis_dec.c in the Vorbis decoder in FFmpeg 0.6.1 and earlier
  allows remote attackers to cause a denial of service (application crash) via
  a crafted .ogg file, related to the vorbis_floor0_decode function.  NOTE:
  this might overlap CVE-2011-0480.
Comment 17 GLSAMaker/CVETool Bot gentoo-dev 2011-10-07 23:46:34 UTC
CVE-2010-3908 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-3908):
  FFmpeg before 0.5.4, as used in MPlayer and other products, allows remote
  attackers to cause a denial of service (memory corruption and application
  crash) or possibly execute arbitrary code via a malformed WMV file.
Comment 18 Alexis Ballier gentoo-dev 2013-08-14 21:13:57 UTC
nothing left to do for media-video@
Comment 19 GLSAMaker/CVETool Bot gentoo-dev 2013-10-25 19:11:17 UTC
This issue was resolved and addressed in
 GLSA 201310-12 at http://security.gentoo.org/glsa/glsa-201310-12.xml
by GLSA coordinator Sean Amoss (ackle).