Oval Definition:oval:org.mitre.oval:def:13661
Revision Date:2014-06-30Version:20
Title:USN-1104-1 -- ffmpeg vulnerabilities
Description:Cesar Bernardini and Felipe Andres Manzano discovered that FFmpeg incorrectly handled certain malformed flic files. If a user were tricked into opening a crafted flic file, an attacker could cause a denial of service via application crash, or possibly execute arbitrary code with the privileges of the user invoking the program. This issue only affected Ubuntu 8.04 LTS, 9.10 and 10.04 LTS. Dan Rosenberg discovered that FFmpeg incorrectly handled certain malformed wmv files. If a user were tricked into opening a crafted wmv file, an attacker could cause a denial of service via application crash, or possibly execute arbitrary code with the privileges of the user invoking the program. This issue only affected Ubuntu 8.04 LTS, 9.10 and 10.04 LTS. It was discovered that FFmpeg incorrectly handled certain malformed ogg files. If a user were tricked into opening a crafted ogg file, an attacker could cause a denial of service via application crash, or possibly execute arbitrary code with the privileges of the user invoking the program. It was discovered that FFmpeg incorrectly handled certain malformed WebM files. If a user were tricked into opening a crafted WebM file, an attacker could cause a denial of service via application crash, or possibly execute arbitrary code with the privileges of the user invoking the program. Dan Rosenberg discovered that FFmpeg incorrectly handled certain malformed RealMedia files. If a user were tricked into opening a crafted RealMedia file, an attacker could cause a denial of service via application crash, or possibly execute arbitrary code with the privileges of the user invoking the program. This issue only affected Ubuntu 8.04 LTS, 9.10 and 10.04 LTS. Dan Rosenberg discovered that FFmpeg incorrectly handled certain malformed VC1 files. If a user were tricked into opening a crafted VC1 file, an attacker could cause a denial of service via application crash, or possibly execute arbitrary code with the privileges of the user invoking the program
Family:unixClass:patch
Status:ACCEPTEDReference(s):CVE-2010-3429
CVE-2010-3908
CVE-2010-4704
CVE-2011-0480
CVE-2011-0722
CVE-2011-0723
USN-1104-1
USN-1104-1
Platform(s):Ubuntu 10.04
Ubuntu 10.10
Ubuntu 8.04
Ubuntu 9.10
Product(s):ffmpeg
Definition Synopsis
  • Release section
  • Ubuntu 8.04 is installed
  • AND Supported architectures section
  • Installed architecture is sparc
  • OR Installed architecture is i386
  • OR Installed architecture is amd64
  • OR Installed architecture is lpia
  • OR Installed architecture is powerpc
  • AND Packages section
  • ffmpeg DPKG is earlier than 3:0.cvs20070307-5ubuntu7.6
  • OR libavcodec-dev DPKG is earlier than 3:0.cvs20070307-5ubuntu7.6
  • OR libavutil-dev DPKG is earlier than 3:0.cvs20070307-5ubuntu7.6
  • OR libpostproc-dev DPKG is earlier than 3:0.cvs20070307-5ubuntu7.6
  • OR libavformat1d DPKG is earlier than 3:0.cvs20070307-5ubuntu7.6
  • OR libswscale1d DPKG is earlier than 3:0.cvs20070307-5ubuntu7.6
  • OR libavcodec1d DPKG is earlier than 3:0.cvs20070307-5ubuntu7.6
  • OR libswscale-dev DPKG is earlier than 3:0.cvs20070307-5ubuntu7.6
  • OR libavutil1d DPKG is earlier than 3:0.cvs20070307-5ubuntu7.6
  • OR libpostproc1d DPKG is earlier than 3:0.cvs20070307-5ubuntu7.6
  • OR libavformat-dev DPKG is earlier than 3:0.cvs20070307-5ubuntu7.6
  • OR Release section
  • Ubuntu 10.10 is installed
  • AND Architecture section
  • Architecture independent section
  • Installed architecture is all
  • AND ffmpeg-doc DPKG is earlier than 4:0.6-2ubuntu6.1
  • OR Architecture depended section
  • Supported architectures section
  • Installed architecture is powerpc
  • OR Installed architecture is armel
  • OR Installed architecture is amd64
  • OR Installed architecture is i386
  • AND Packages section
  • ffmpeg-dbg DPKG is earlier than 4:0.6-2ubuntu6.1
  • OR ffmpeg DPKG is earlier than 4:0.6-2ubuntu6.1
  • OR libswscale0 DPKG is earlier than 4:0.6-2ubuntu6.1
  • OR libavcodec52 DPKG is earlier than 4:0.6-2ubuntu6.1
  • OR libavformat52 DPKG is earlier than 4:0.6-2ubuntu6.1
  • OR libpostproc-dev DPKG is earlier than 4:0.6-2ubuntu6.1
  • OR libavfilter-dev DPKG is earlier than 4:0.6-2ubuntu6.1
  • OR libpostproc51 DPKG is earlier than 4:0.6-2ubuntu6.1
  • OR libavdevice52 DPKG is earlier than 4:0.6-2ubuntu6.1
  • OR libavcodec-dev DPKG is earlier than 4:0.6-2ubuntu6.1
  • OR libswscale-dev DPKG is earlier than 4:0.6-2ubuntu6.1
  • OR libavutil-dev DPKG is earlier than 4:0.6-2ubuntu6.1
  • OR libavformat-dev DPKG is earlier than 4:0.6-2ubuntu6.1
  • OR libavfilter1 DPKG is earlier than 4:0.6-2ubuntu6.1
  • OR libavutil50 DPKG is earlier than 4:0.6-2ubuntu6.1
  • OR libavdevice-dev DPKG is earlier than 4:0.6-2ubuntu6.1
  • OR Release section
  • Ubuntu 9.10 is installed
  • AND Architecture section
  • Architecture independent section
  • Installed architecture is all
  • AND ffmpeg-doc DPKG is earlier than 4:0.5+svn20090706-2ubuntu2.3
  • OR Architecture depended section
  • Supported architectures section
  • Installed architecture is amd64
  • OR Installed architecture is sparc
  • OR Installed architecture is powerpc
  • OR Installed architecture is i386
  • OR Installed architecture is armel
  • OR Installed architecture is lpia
  • AND Packages section
  • ffmpeg-dbg DPKG is earlier than 4:0.5+svn20090706-2ubuntu2.3
  • OR ffmpeg DPKG is earlier than 4:0.5+svn20090706-2ubuntu2.3
  • OR libswscale0 DPKG is earlier than 4:0.5+svn20090706-2ubuntu2.3
  • OR libavcodec52 DPKG is earlier than 4:0.5+svn20090706-2ubuntu2.3
  • OR libavformat52 DPKG is earlier than 4:0.5+svn20090706-2ubuntu2.3
  • OR libpostproc-dev DPKG is earlier than 4:0.5+svn20090706-2ubuntu2.3
  • OR libavfilter-dev DPKG is earlier than 4:0.5+svn20090706-2ubuntu2.3
  • OR libpostproc51 DPKG is earlier than 4:0.5+svn20090706-2ubuntu2.3
  • OR libavdevice52 DPKG is earlier than 4:0.5+svn20090706-2ubuntu2.3
  • OR libavcodec-dev DPKG is earlier than 4:0.5+svn20090706-2ubuntu2.3
  • OR libswscale-dev DPKG is earlier than 4:0.5+svn20090706-2ubuntu2.3
  • OR libavutil-dev DPKG is earlier than 4:0.5+svn20090706-2ubuntu2.3
  • OR libavutil49 DPKG is earlier than 4:0.5+svn20090706-2ubuntu2.3
  • OR libavformat-dev DPKG is earlier than 4:0.5+svn20090706-2ubuntu2.3
  • OR libavfilter0 DPKG is earlier than 4:0.5+svn20090706-2ubuntu2.3
  • OR libavdevice-dev DPKG is earlier than 4:0.5+svn20090706-2ubuntu2.3
  • OR Release section
  • Ubuntu 10.04 is installed
  • AND Architecture section
  • Architecture independent section
  • Installed architecture is all
  • AND ffmpeg-doc DPKG is earlier than 4:0.5.1-1ubuntu1.1
  • OR Architecture depended section
  • Supported architectures section
  • Installed architecture is sparc
  • OR Installed architecture is armel
  • OR Installed architecture is amd64
  • OR Installed architecture is i386
  • AND Packages section
  • ffmpeg-dbg DPKG is earlier than 4:0.5.1-1ubuntu1.1
  • OR ffmpeg DPKG is earlier than 4:0.5.1-1ubuntu1.1
  • OR libswscale0 DPKG is earlier than 4:0.5.1-1ubuntu1.1
  • OR libavcodec52 DPKG is earlier than 4:0.5.1-1ubuntu1.1
  • OR libavformat52 DPKG is earlier than 4:0.5.1-1ubuntu1.1
  • OR libpostproc-dev DPKG is earlier than 4:0.5.1-1ubuntu1.1
  • OR libavfilter-dev DPKG is earlier than 4:0.5.1-1ubuntu1.1
  • OR libpostproc51 DPKG is earlier than 4:0.5.1-1ubuntu1.1
  • OR libavdevice52 DPKG is earlier than 4:0.5.1-1ubuntu1.1
  • OR libavcodec-dev DPKG is earlier than 4:0.5.1-1ubuntu1.1
  • OR libswscale-dev DPKG is earlier than 4:0.5.1-1ubuntu1.1
  • OR libavutil-dev DPKG is earlier than 4:0.5.1-1ubuntu1.1
  • OR libavutil49 DPKG is earlier than 4:0.5.1-1ubuntu1.1
  • OR libavformat-dev DPKG is earlier than 4:0.5.1-1ubuntu1.1
  • OR libavfilter0 DPKG is earlier than 4:0.5.1-1ubuntu1.1
  • OR libavdevice-dev DPKG is earlier than 4:0.5.1-1ubuntu1.1
  • BACK