![]() |
Home ▼ Bookkeeping
Online ▼ Security
Audits ▼
Managed
DNS ▼
About
Order
FAQ
Acceptable Use Policy
Dynamic DNS Clients
Configure Domains Dyanmic DNS Update Password Network
Monitor ▼
Enterprise Package
Advanced Package
Standard Package
Free Trial
FAQ
Price/Feature Summary
Order/Renew
Examples
Configure/Status Alert Profiles | ||
Test ID: | 1.3.6.1.4.1.25623.1.1.10.2014.0491 |
Category: | Mageia Linux Local Security Checks |
Title: | Mageia: Security Advisory (MGASA-2014-0491) |
Summary: | The remote host is missing an update for the 'avidemux' package(s) announced via the MGASA-2014-0491 advisory. |
Description: | Summary: The remote host is missing an update for the 'avidemux' package(s) announced via the MGASA-2014-0491 advisory. Vulnerability Insight: A heap-based buffer overflow in the encode_slice function in libavcodec/proresenc_kostya.c in FFmpeg before 1.2.9 can cause a crash, allowing a malicious image file to cause a denial of service (CVE-2014-5271). libavcodec/iff.c in FFmpeg before 1.2.9 allows an attacker to have an unspecified impact via a crafted iff image, which triggers an out-of-bounds array access, related to the rgb8 and rgbn formats (CVE-2014-5272). libavcodec/mjpegdec.c in FFmpeg before 1.2.9 considers only dimension differences, and not bits-per-pixel differences, when determining whether an image size has changed, which allows remote attackers to cause a denial of service (out-of-bounds access) or possibly have unspecified other impact via crafted MJPEG data (CVE-2014-8541). libavcodec/utils.c in FFmpeg before 1.2.9 omits a certain codec ID during enforcement of alignment, which allows remote attackers to cause a denial of service (out-of-bounds access) or possibly have unspecified other impact via crafted JV data (CVE-2014-8542). libavcodec/mmvideo.c in FFmpeg before 1.2.9 does not consider all lines of HHV Intra blocks during validation of image height, which allows remote attackers to cause a denial of service (out-of-bounds access) or possibly have unspecified other impact via crafted MM video data (CVE-2014-8543). libavcodec/tiff.c in FFmpeg before 1.2.9 does not properly validate bits-per-pixel fields, which allows remote attackers to cause a denial of service (out-of-bounds access) or possibly have unspecified other impact via crafted TIFF data (CVE-2014-8544). libavcodec/pngdec.c in FFmpeg before 1.2.9 accepts the monochrome-black format without verifying that the bits-per-pixel value is 1, which allows remote attackers to cause a denial of service (out-of-bounds access) or possibly have unspecified other impact via crafted PNG data (CVE-2014-8545). Integer underflow in libavcodec/cinepak.c in FFmpeg before 1.2.9 allows remote attackers to cause a denial of service (out-of-bounds access) or possibly have unspecified other impact via crafted Cinepak video data (CVE-2014-8546). libavcodec/gifdec.c in FFmpeg before 1.2.9 does not properly compute image heights, which allows remote attackers to cause a denial of service (out-of-bounds access) or possibly have unspecified other impact via crafted GIF data (CVE-2014-8547). Off-by-one error in libavcodec/smc.c in FFmpeg before 1.2.9 allows remote attackers to cause a denial of service (out-of-bounds access) or possibly have unspecified other impact via crafted Quicktime Graphics (aka SMC) video data (CVE-2014-8548). Avidemux built with a bundled set of FFmpeg libraries. The bundled FFmpeg version have been updated from 1.2.7 to 1.2.10 to fix these security issues and other bugs fixed upstream in FFmpeg. Affected Software/OS: 'avidemux' package(s) on Mageia 4. Solution: Please install the updated package(s). CVSS Score: 7.5 CVSS Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P |
Cross-Ref: |
Common Vulnerability Exposure (CVE) ID: CVE-2014-5271 BugTraq ID: 69250 http://www.securityfocus.com/bid/69250 https://security.gentoo.org/glsa/201603-06 http://www.osvdb.org/111725 Common Vulnerability Exposure (CVE) ID: CVE-2014-5272 http://www.openwall.com/lists/oss-security/2014/08/16/6 Common Vulnerability Exposure (CVE) ID: CVE-2014-8541 http://www.ubuntu.com/usn/USN-2944-1 Common Vulnerability Exposure (CVE) ID: CVE-2014-8542 https://lists.debian.org/debian-lts-announce/2019/02/msg00005.html http://www.ubuntu.com/usn/USN-2534-1 Common Vulnerability Exposure (CVE) ID: CVE-2014-8543 Common Vulnerability Exposure (CVE) ID: CVE-2014-8544 Common Vulnerability Exposure (CVE) ID: CVE-2014-8545 Common Vulnerability Exposure (CVE) ID: CVE-2014-8546 Common Vulnerability Exposure (CVE) ID: CVE-2014-8547 Common Vulnerability Exposure (CVE) ID: CVE-2014-8548 |
Copyright | Copyright (C) 2022 Greenbone AG |
This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit. To run a free test of this vulnerability against your system, register below. |