Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 842267 (CVE-2022-1475) - <media-video/ffmpeg-4.4.2: integer overflow vulnerability
Summary: <media-video/ffmpeg-4.4.2: integer overflow vulnerability
Alias: CVE-2022-1475
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor (vote)
Assignee: Gentoo Security
Whiteboard: B3 [glsa? cleanup]
Depends on: 848879
  Show dependency tree
Reported: 2022-05-03 00:38 UTC by John Helmert III
Modified: 2022-09-03 05:27 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Note You need to log in before you can comment on or make changes to this bug.
Description John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2022-05-03 00:38:55 UTC

An integer overflow vulnerability was found in FFmpeg 5.0.1 and in previous versions in g729_parse() in llibavcodec/g729_parser.c when processing a specially crafted file.

Comment 1 Larry the Git Cow gentoo-dev 2022-05-03 01:12:23 UTC
The bug has been referenced in the following commit(s):

commit bb33595d7124b0e0ce9f569c2383dea5215203fc
Author:     Sam James <>
AuthorDate: 2022-05-03 01:11:11 +0000
Commit:     Sam James <>
CommitDate: 2022-05-03 01:11:11 +0000

    media-video/ffmpeg: add 4.4.2
    Signed-off-by: Sam James <>

 media-video/ffmpeg/Manifest            |   2 +
 media-video/ffmpeg/ffmpeg-4.4.2.ebuild | 581 +++++++++++++++++++++++++++++++++
 2 files changed, 583 insertions(+)
Comment 2 Larry the Git Cow gentoo-dev 2022-09-03 05:27:14 UTC
The bug has been referenced in the following commit(s):

commit 31baf58256ca04e305510ce86df9f6d83948f853
Author:     Sam James <>
AuthorDate: 2022-09-03 05:24:50 +0000
Commit:     Sam James <>
CommitDate: 2022-09-03 05:25:22 +0000

    media-video/ffmpeg: add 4.2.7
    Fixes a bunch of CVEs that we've had fixed in newer versions
    for a while, but until we can clean up 4.2.x, we may as well
    bump to the latest in that series...
    Signed-off-by: Sam James <>

 media-video/ffmpeg/Manifest                        |   1 +
 media-video/ffmpeg/ffmpeg-4.2.7.ebuild             | 556 +++++++++++++++++++++
 .../ffmpeg-4.2.7-libsdl2-new-version-scheme.patch  |  26 +
 3 files changed, 583 insertions(+)