Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 781146 (CVE-2021-30123) - <media-video/ffmpeg-4.4: exploitable buffer overflow
Summary: <media-video/ffmpeg-4.4: exploitable buffer overflow
Status: CONFIRMED
Alias: CVE-2021-30123
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal major (vote)
Assignee: Gentoo Security
URL: https://git.videolan.org/?p=ffmpeg.gi...
Whiteboard: A2 [stable?]
Keywords:
Depends on: 782811 785247 782412
Blocks:
  Show dependency tree
 
Reported: 2021-04-08 14:45 UTC by John Helmert III
Modified: 2021-04-27 05:11 UTC (History)
1 user (show)

See Also:
Package list:
media-video/ffmpeg-4.4 *
Runtime testing required: ---
nattka: sanity-check+


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description John Helmert III gentoo-dev Security 2021-04-08 14:45:31 UTC
CVE-2021-30123:

FFmpeg <=4.3 contains a buffer overflow vulnerability in libavcodec through a crafted file that may lead to remote code execution.


Patch at $URL but seems it's not part of any tag yet.
Comment 1 jospezial 2021-04-09 11:59:28 UTC
It is in just released 4.4 .
Comment 3 John Helmert III gentoo-dev Security 2021-04-09 14:17:22 UTC
(In reply to jospezial from comment #1)
> It is in just released 4.4 .

Thanks! Maintainers, please bump.
Comment 4 jospezial 2021-04-09 21:44:24 UTC
https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=ddb6d10608a9396bb123add897b15fe01538ce68
media-video/ffmpeg: bump to 4.4
Comment 5 Sam James archtester gentoo-dev Security 2021-04-09 22:06:46 UTC
(In reply to jospezial from comment #4)
> https://gitweb.gentoo.org/repo/gentoo.git/commit/
> ?id=ddb6d10608a9396bb123add897b15fe01538ce68
> media-video/ffmpeg: bump to 4.4

Thanks!