SUSE-SU-2019:3184-1
Dashboard / Vulnerabilities / SUSE-SU-2019:3184-1
SUSE-SU-2019:3184-1
Summary: Security update for ffmpeg
Details: This update for ffmpeg fixes the following issues: Security issues fixed: - CVE-2019-17542: Fixed a heap-buffer overflow in vqa_decode_chunk due to an out-of-array access (bsc#1154064). - CVE-2019-12730: Fixed an uninitialized use of variables due to an improper check (bsc#1137526). - CVE-2019-9718: Fixed a denial of service in the subtitle decode (bsc#1129715). - CVE-2018-13301: Fixed a denial of service while converting a crafted AVI file to MPEG4 (bsc#1100352).
References: https://www.suse.com/support/update/announcement/2019/suse-su-20193184-1/, https://bugzilla.suse.com/1100352, https://bugzilla.suse.com/1129715, https://bugzilla.suse.com/1137526, https://bugzilla.suse.com/1154064, https://www.suse.com/security/cve/CVE-2018-13301, https://www.suse.com/security/cve/CVE-2019-12730, https://www.suse.com/security/cve/CVE-2019-17542, https://www.suse.com/security/cve/CVE-2019-9718
Affected packages
Package
Name: ffmpeg
Purl: pkg:rpm/suse/ffmpeg&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Desktop%20Applications%2015
Affected ranges
Type: ECOSYSTEM
Events:
