SUSE-SU-2024:1468-1
Dashboard / Vulnerabilities / SUSE-SU-2024:1468-1
SUSE-SU-2024:1468-1
Summary: Security update for ffmpeg
Details: This update for ffmpeg fixes the following issues: - CVE-2024-31578: Fixed heap use-after-free via av_hwframe_ctx_init() when vulkan_frames init failed (bsc#1223070) - CVE-2023-49502: Fixed heap buffer overflow via the ff_bwdif_filter_intra_c function in libavfilter/bwdifdsp.c (bsc#1223235) Adding references for already fixed issues: - CVE-2021-38091: Fixed integer overflow in function filter16_sobel in libavfilter/vf_convolution.c (bsc#1190732) - CVE-2021-38090: Fixed integer overflow in function filter16_roberts in libavfilter/vf_convolution.c (bsc#1190731) - CVE-2020-20898: Fixed integer overflow vulnerability in function filter16_prewitt in libavfilter/vf_convolution.c (bsc#1190724) - CVE-2020-20901: Fixed buffer overflow vulnerability in function filter_frame in libavfilter/vf_fieldorder.c (bsc#1190728) - CVE-2020-20900: Fixed buffer overflow vulnerability in function gaussian_blur in libavfilter/vf_edgedetect.c (bsc#1190727) - CVE-2020-20894: Fixed buffer Overflow vulnerability in function gaussian_blur in libavfilter/vf_edgedetect.c (bsc#1190721)
References: https://www.suse.com/support/update/announcement/2024/suse-su-20241468-1/, https://bugzilla.suse.com/1190721, https://bugzilla.suse.com/1190724, https://bugzilla.suse.com/1190727, https://bugzilla.suse.com/1190728, https://bugzilla.suse.com/1190731, https://bugzilla.suse.com/1190732, https://bugzilla.suse.com/1223070, https://bugzilla.suse.com/1223235, https://www.suse.com/security/cve/CVE-2020-20894, https://www.suse.com/security/cve/CVE-2020-20898, https://www.suse.com/security/cve/CVE-2020-20900, https://www.suse.com/security/cve/CVE-2020-20901, https://www.suse.com/security/cve/CVE-2021-38090, https://www.suse.com/security/cve/CVE-2021-38091, https://www.suse.com/security/cve/CVE-2021-38094, https://www.suse.com/security/cve/CVE-2023-49502, https://www.suse.com/security/cve/CVE-2024-31578
Affected packages
Package
Name: ffmpeg
Purl: pkg:rpm/suse/ffmpeg&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Desktop%20Applications%2015%20SP5
Affected ranges
Type: ECOSYSTEM
Events:
