Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.70239
Category:Debian Local Security Checks
Title:Debian: Security Advisory (DSA-2306-1)
Summary:The remote host is missing an update for the Debian 'ffmpeg' package(s) announced via the DSA-2306-1 advisory.
Description:Summary:
The remote host is missing an update for the Debian 'ffmpeg' package(s) announced via the DSA-2306-1 advisory.

Vulnerability Insight:
Several vulnerabilities have been discovered in FFmpeg, a multimedia player, server and encoder. The Common Vulnerabilities and Exposures project identifies the following problems:

CVE-2010-3908

FFmpeg before 0.5.4, allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a malformed WMV file.

CVE-2010-4704

libavcodec/vorbis_dec.c in the Vorbis decoder in FFmpeg allows remote attackers to cause a denial of service (application crash) via a crafted Ogg file, related to the vorbis_floor0_decode function.

CVE-2011-0480

Multiple buffer overflows in vorbis_dec.c in the Vorbis decoder in FFmpeg allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact via a crafted WebM file, related to buffers for the channel floor and the channel residue.

CVE-2011-0722

FFmpeg allows remote attackers to cause a denial of service (heap memory corruption and application crash) or possibly execute arbitrary code via a malformed RealMedia file.

For the stable distribution (squeeze), this problem has been fixed in version 4:0.5.4-1.

Security support for ffmpeg has been discontinued for the oldstable distribution (lenny). The current version in oldstable is not supported by upstream anymore and is affected by several security issues. Backporting fixes for these and any future issues has become unfeasible and therefore we need to drop our security support for the version in oldstable.

We recommend that you upgrade your ffmpeg packages.

Affected Software/OS:
'ffmpeg' package(s) on Debian 6.

Solution:
Please install the updated package(s).

CVSS Score:
10.0

CVSS Vector:
AV:N/AC:L/Au:N/C:C/I:C/A:C

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2010-3908
Debian Security Information: DSA-2306 (Google Search)
http://www.debian.org/security/2011/dsa-2306
http://www.mandriva.com/security/advisories?name=MDVSA-2011:061
http://www.ubuntu.com/usn/usn-1104-1/
Common Vulnerability Exposure (CVE) ID: CVE-2010-4704
BugTraq ID: 46294
http://www.securityfocus.com/bid/46294
Debian Security Information: DSA-2165 (Google Search)
http://www.debian.org/security/2011/dsa-2165
http://www.mandriva.com/security/advisories?name=MDVSA-2011:060
http://www.mandriva.com/security/advisories?name=MDVSA-2011:062
http://www.mandriva.com/security/advisories?name=MDVSA-2011:088
http://www.mandriva.com/security/advisories?name=MDVSA-2011:089
http://www.mandriva.com/security/advisories?name=MDVSA-2011:112
http://www.mandriva.com/security/advisories?name=MDVSA-2011:114
http://secunia.com/advisories/43323
http://www.vupen.com/english/advisories/2011/1241
Common Vulnerability Exposure (CVE) ID: CVE-2011-0480
BugTraq ID: 45788
http://www.securityfocus.com/bid/45788
http://article.gmane.org/gmane.comp.video.ffmpeg.devel/122703
http://osvdb.org/70463
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14380
http://secunia.com/advisories/42951
XForce ISS Database: chrome-vorbis-bo(64671)
https://exchange.xforce.ibmcloud.com/vulnerabilities/64671
Common Vulnerability Exposure (CVE) ID: CVE-2011-0722
BugTraq ID: 47149
http://www.securityfocus.com/bid/47149
Common Vulnerability Exposure (CVE) ID: CVE-2011-0723
BugTraq ID: 47151
http://www.securityfocus.com/bid/47151
http://ffmpeg.mplayerhq.hu/
Common Vulnerability Exposure (CVE) ID: CVE-2011-2160
BugTraq ID: 47956
http://www.securityfocus.com/bid/47956
Common Vulnerability Exposure (CVE) ID: CVE-2011-2161
http://packetstorm.linuxsecurity.com/1103-exploits/vlc105-dos.txt
Common Vulnerability Exposure (CVE) ID: CVE-2011-2162
http://www.mandriva.com/security/advisories?name=MDVSA-2011:059
CopyrightCopyright (C) 2011 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.