Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.70554
Category:Debian Local Security Checks
Title:Debian: Security Advisory (DSA-2336-1)
Summary:The remote host is missing an update for the Debian 'ffmpeg' package(s) announced via the DSA-2336-1 advisory.
Description:Summary:
The remote host is missing an update for the Debian 'ffmpeg' package(s) announced via the DSA-2336-1 advisory.

Vulnerability Insight:
Multiple vulnerabilities were found in FFmpeg, a multimedia player, server and encoder:

CVE-2011-3362

An integer signedness error in decode_residual_block function of the Chinese AVS video (CAVS) decoder in libavcodec can lead to denial of service (memory corruption and application crash) or possible code execution via a crafted CAVS file.

CVE-2011-3973/CVE-2011-3974 Multiple errors in the Chinese AVS video (CAVS) decoder can lead to denial of service (memory corruption and application crash) via an invalid bitstream.

CVE-2011-3504

A memory allocation problem in the Matroska format decoder can lead to code execution via a crafted file.

For the stable distribution (squeeze), this problem has been fixed in version 4:0.5.5-1.

For the unstable distribution (sid), this problem has been fixed in version 4:0.7.2-1 of the libav source package.

Security support for ffmpeg has been discontinued for the oldstable distribution (lenny) before in DSA 2306. The current version in oldstable is not supported by upstream anymore and is affected by several security issues. Backporting fixes for these and any future issues has become unfeasible and therefore we needed to drop our security support for the version in oldstable.

We recommend that you upgrade your ffmpeg packages.

Affected Software/OS:
'ffmpeg' package(s) on Debian 6.

Solution:
Please install the updated package(s).

CVSS Score:
9.3

CVSS Vector:
AV:N/AC:M/Au:N/C:C/I:C/A:C

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2011-3362
http://www.ocert.org/advisories/ocert-2011-002.html
http://www.openwall.com/lists/oss-security/2011/09/13/4
http://www.openwall.com/lists/oss-security/2011/09/14/8
http://secunia.com/advisories/45532
Common Vulnerability Exposure (CVE) ID: CVE-2011-3504
http://www.mandriva.com/security/advisories?name=MDVSA-2012:074
http://www.mandriva.com/security/advisories?name=MDVSA-2012:075
http://www.mandriva.com/security/advisories?name=MDVSA-2012:076
http://technet.microsoft.com/en-us/security/msvr/msvr11-011
http://www.ffmpeg.org/releases/ffmpeg-0.7.5.changelog
http://www.ffmpeg.org/releases/ffmpeg-0.8.4.changelog
http://www.osvdb.org/75621
http://ubuntu.com/usn/usn-1320-1
http://ubuntu.com/usn/usn-1333-1
Common Vulnerability Exposure (CVE) ID: CVE-2011-3973
Common Vulnerability Exposure (CVE) ID: CVE-2011-3974
CopyrightCopyright (C) 2012 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.