SUSE-SU-2018:2305-1
Dashboard / Vulnerabilities / SUSE-SU-2018:2305-1
SUSE-SU-2018:2305-1
Summary: Security update for ffmpeg
Details: This update for ffmpeg fixes the following issues: Security issues fixed: - CVE-2018-13302: Fixed out of array access issue (bsc#1100356). - CVE-2018-1999010: Fixed multiple out of array access vulnerabilities in the mms protocol that could result in accessing out of bound data via specially crafted input files (bnc#1102899) - CVE-2018-1999011: Fixed a heap buffer overflow in asf_o format demuxer that could result in remote code execution (bnc#1102689) - CVE-2018-1999012: Fixed an infinite loop vulnerability in pva format demuxer that could result in excessive amount of ressource allocation like CPU an RAM (CVE-2018-1999012 bnc#1102688). - CVE-2018-1999013: Fixed an use-after-free vulnerability in the realmedia demuxer that could allow remote attackers to read heap memory (bnc#1102687)
References: https://www.suse.com/support/update/announcement/2018/suse-su-20182305-1/, https://bugzilla.suse.com/1100356, https://bugzilla.suse.com/1102687, https://bugzilla.suse.com/1102688, https://bugzilla.suse.com/1102689, https://bugzilla.suse.com/1102899, https://www.suse.com/security/cve/CVE-2018-13302, https://www.suse.com/security/cve/CVE-2018-1999010, https://www.suse.com/security/cve/CVE-2018-1999011, https://www.suse.com/security/cve/CVE-2018-1999012, https://www.suse.com/security/cve/CVE-2018-1999013
Affected packages
Package
Name: ffmpeg
Purl: pkg:rpm/suse/ffmpeg&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Desktop%20Applications%2015
Affected ranges
Type: ECOSYSTEM
Events:
