Debian Security Advisory

DSA-2471-1 ffmpeg -- several vulnerabilities

Date Reported:
13 May 2012
Affected Packages:
ffmpeg
Vulnerable:
Yes
Security database references:
In Mitre's CVE dictionary: CVE-2011-3892, CVE-2011-3893, CVE-2011-3895, CVE-2011-3929, CVE-2011-3936, CVE-2011-3940, CVE-2011-3947, CVE-2012-0853, CVE-2012-0947.
More information:

Several vulnerabilities have been discovered in FFmpeg, a multimedia player, server and encoder. Multiple input validations in the decoders/ demuxers for Westwood Studios VQA, Apple MJPEG-B, Theora, Matroska, Vorbis, Sony ATRAC3, DV, NSV, files could lead to the execution of arbitrary code.

These issues were discovered by Aki Helin, Mateusz Jurczyk, Gynvael Coldwind, and Michael Niedermayer.

For the stable distribution (squeeze), this problem has been fixed in version 4:0.5.8-1.

For the unstable distribution (sid), this problem has been fixed in version 6:0.8.2-1 of libav.

We recommend that you upgrade your ffmpeg packages.