Executive Summary
Summary | |
---|---|
Title | ffmpeg security update |
Informations | |||
---|---|---|---|
Name | DSA-2471 | First vendor Publication | 2012-05-13 |
Vendor | Debian | Last vendor Modification | 2012-05-13 |
Severity (Vendor) | N/A | Revision | 1 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:L/Au:N/C:P/I:P/A:P) | |||
---|---|---|---|
Cvss Base Score | 7.5 | Attack Range | Network |
Cvss Impact Score | 6.4 | Attack Complexity | Low |
Cvss Expoit Score | 10 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
Several vulnerabilities have been discovered in FFmpeg, a multimedia player, server and encoder. Multiple input validations in the decoders/ demuxers for Westwood Studios VQA, Apple MJPEG-B, Theora, Matroska, Vorbis, Sony ATRAC3, DV, NSV, files could lead to the execution of arbitrary code. These issues were discovered by Aki Helin, Mateusz Jurczyk, Gynvael Coldwind, and Michael Niedermayer. For the stable distribution (squeeze), this problem has been fixed in version 4:0.5.8-1. For the unstable distribution (sid), this problem has been fixed in version 6:0.8.2-1 of libav. We recommend that you upgrade your ffmpeg packages. |
Original Source
Url : http://www.debian.org/security/2012/dsa-2471 |
CWE : Common Weakness Enumeration
% | Id | Name |
---|---|---|
44 % | CWE-119 | Failure to Constrain Operations within the Bounds of a Memory Buffer |
22 % | CWE-20 | Improper Input Validation |
11 % | CWE-787 | Out-of-bounds Write (CWE/SANS Top 25) |
11 % | CWE-415 | Double Free |
11 % | CWE-125 | Out-of-bounds Read |
OVAL Definitions
Definition Id: oval:org.mitre.oval:def:13551 | |||
Oval ID: | oval:org.mitre.oval:def:13551 | ||
Title: | Heap-based buffer overflow in the Vorbis decoder in Google Chrome before 15.0.874.120 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted stream. | ||
Description: | Heap-based buffer overflow in the Vorbis decoder in Google Chrome before 15.0.874.120 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted stream. | ||
Family: | windows | Class: | vulnerability |
Reference(s): | CVE-2011-3895 | Version: | 15 |
Platform(s): | Microsoft Windows 7 Microsoft Windows Server 2008 Microsoft Windows Vista Microsoft Windows Server 2003 Microsoft Windows XP Microsoft Windows 2000 | Product(s): | Google Chrome |
Definition Synopsis: | |||
|
Definition Id: oval:org.mitre.oval:def:14267 | |||
Oval ID: | oval:org.mitre.oval:def:14267 | ||
Title: | Google Chrome before 15.0.874.120 does not properly implement the MKV and Vorbis media handlers, which allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors. | ||
Description: | Google Chrome before 15.0.874.120 does not properly implement the MKV and Vorbis media handlers, which allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors. | ||
Family: | windows | Class: | vulnerability |
Reference(s): | CVE-2011-3893 | Version: | 15 |
Platform(s): | Microsoft Windows 7 Microsoft Windows Server 2008 Microsoft Windows Vista Microsoft Windows Server 2003 Microsoft Windows XP Microsoft Windows 2000 | Product(s): | Google Chrome |
Definition Synopsis: | |||
|
Definition Id: oval:org.mitre.oval:def:14484 | |||
Oval ID: | oval:org.mitre.oval:def:14484 | ||
Title: | Double free vulnerability in the Theora decoder in Google Chrome before 15.0.874.120 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted stream. | ||
Description: | Double free vulnerability in the Theora decoder in Google Chrome before 15.0.874.120 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted stream. | ||
Family: | windows | Class: | vulnerability |
Reference(s): | CVE-2011-3892 | Version: | 15 |
Platform(s): | Microsoft Windows 7 Microsoft Windows Server 2008 Microsoft Windows Vista Microsoft Windows Server 2003 Microsoft Windows XP Microsoft Windows 2000 | Product(s): | Google Chrome |
Definition Synopsis: | |||
|
Definition Id: oval:org.mitre.oval:def:17641 | |||
Oval ID: | oval:org.mitre.oval:def:17641 | ||
Title: | USN-1478-1 -- libav vulnerabilities | ||
Description: | Libav could be made to crash or run programs as your login if it opened a specially crafted file. | ||
Family: | unix | Class: | patch |
Reference(s): | USN-1478-1 CVE-2011-3929 CVE-2011-3936 CVE-2011-3940 CVE-2011-3945 CVE-2011-3947 CVE-2011-3951 CVE-2011-3952 CVE-2011-4031 CVE-2012-0848 CVE-2012-0850 CVE-2012-0851 CVE-2012-0852 CVE-2012-0853 CVE-2012-0858 CVE-2012-0859 CVE-2012-0947 | Version: | 5 |
Platform(s): | Ubuntu 12.04 Ubuntu 11.10 Ubuntu 11.04 | Product(s): | libav |
Definition Synopsis: | |||
|
Definition Id: oval:org.mitre.oval:def:17815 | |||
Oval ID: | oval:org.mitre.oval:def:17815 | ||
Title: | USN-1479-1 -- ffmpeg vulnerabilities | ||
Description: | FFmpeg could be made to crash or run programs as your login if it opened a specially crafted file. | ||
Family: | unix | Class: | patch |
Reference(s): | USN-1479-1 CVE-2011-3929 CVE-2011-3936 CVE-2011-3940 CVE-2011-3947 CVE-2011-3951 CVE-2011-3952 CVE-2012-0851 CVE-2012-0852 CVE-2012-0853 CVE-2012-0858 CVE-2012-0859 CVE-2012-0947 | Version: | 5 |
Platform(s): | Ubuntu 10.04 | Product(s): | ffmpeg |
Definition Synopsis: | |||
Definition Id: oval:org.mitre.oval:def:18368 | |||
Oval ID: | oval:org.mitre.oval:def:18368 | ||
Title: | DSA-2471-1 ffmpeg - several | ||
Description: | Several vulnerabilities have been discovered in FFmpeg, a multimedia player, server and encoder. Multiple input validations in the decoders/ demuxers for Westwood Studios VQA, Apple MJPEG-B, Theora, Matroska, Vorbis, Sony ATRAC3, DV, NSV, files could lead to the execution of arbitrary code. | ||
Family: | unix | Class: | patch |
Reference(s): | DSA-2471-1 CVE-2011-3892 CVE-2011-3893 CVE-2011-3895 CVE-2011-3929 CVE-2011-3936 CVE-2011-3940 CVE-2011-3947 CVE-2012-0853 CVE-2012-0947 | Version: | 5 |
Platform(s): | Debian GNU/Linux 6.0 Debian GNU/kFreeBSD 6.0 | Product(s): | ffmpeg |
Definition Synopsis: | |||
|
CPE : Common Platform Enumeration
OpenVAS Exploits
Date | Description |
---|---|
2013-09-18 | Name : Debian Security Advisory DSA 2471-1 (ffmpeg - several vulnerabilities) File : nvt/deb_2471_1.nasl |
2012-10-22 | Name : Gentoo Security Advisory GLSA 201210-06 (libav) File : nvt/glsa_201210_06.nasl |
2012-08-03 | Name : Mandriva Update for ffmpeg MDVSA-2012:075 (ffmpeg) File : nvt/gb_mandriva_MDVSA_2012_075.nasl |
2012-08-03 | Name : Mandriva Update for ffmpeg MDVSA-2012:076 (ffmpeg) File : nvt/gb_mandriva_MDVSA_2012_076.nasl |
2012-06-19 | Name : Ubuntu Update for libav USN-1478-1 File : nvt/gb_ubuntu_USN_1478_1.nasl |
2012-06-19 | Name : Ubuntu Update for ffmpeg USN-1479-1 File : nvt/gb_ubuntu_USN_1479_1.nasl |
2012-02-12 | Name : Gentoo Security Advisory GLSA 201111-05 (chromium v8) File : nvt/glsa_201111_05.nasl |
2011-11-15 | Name : Google Chrome Multiple Vulnerabilities - November11 (Linux) File : nvt/gb_google_chrome_mult_vuln_nov11_lin.nasl |
2011-11-15 | Name : Google Chrome Multiple Vulnerabilities - November11 (Mac OS X) File : nvt/gb_google_chrome_mult_vuln_nov11_macosx.nasl |
2011-11-14 | Name : Google Chrome Multiple Vulnerabilities - November11 (Windows) File : nvt/gb_google_chrome_mult_vuln_nov11_win.nasl |
2011-01-24 | Name : FreeBSD Ports: chromium File : nvt/freebsd_chromium.nasl |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
77035 | Google Chrome Vorbis Decoder Unspecified Remote Overflow |
77033 | Google Chrome MKV / Vorbis Media Handler Out-of-bounds Read Unspecified Remot... |
77032 | Google Chrome Theora Decoder Unspecified Double-free Remote Issue |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2013-10-27 | Name : The remote Gentoo host is missing one or more security-related patches. File : gentoo_GLSA-201310-12.nasl - Type : ACT_GATHER_INFO |
2013-08-21 | Name : The remote FreeBSD host is missing a security-related update. File : freebsd_pkg_4d087b35099011e3a9f4bcaec565249c.nasl - Type : ACT_GATHER_INFO |
2012-10-22 | Name : The remote Gentoo host is missing one or more security-related patches. File : gentoo_GLSA-201210-06.nasl - Type : ACT_GATHER_INFO |
2012-09-06 | Name : The remote Mandriva Linux host is missing one or more security updates. File : mandriva_MDVSA-2012-076.nasl - Type : ACT_GATHER_INFO |
2012-06-19 | Name : The remote Ubuntu host is missing one or more security-related patches. File : ubuntu_USN-1478-1.nasl - Type : ACT_GATHER_INFO |
2012-06-19 | Name : The remote Ubuntu host is missing one or more security-related patches. File : ubuntu_USN-1479-1.nasl - Type : ACT_GATHER_INFO |
2012-05-15 | Name : The remote Debian host is missing a security-related update. File : debian_DSA-2471.nasl - Type : ACT_GATHER_INFO |
2012-05-15 | Name : The remote Mandriva Linux host is missing one or more security updates. File : mandriva_MDVSA-2012-075.nasl - Type : ACT_GATHER_INFO |
2011-11-22 | Name : The remote Gentoo host is missing one or more security-related patches. File : gentoo_GLSA-201111-05.nasl - Type : ACT_GATHER_INFO |
2011-11-11 | Name : The remote host contains a web browser that is affected by multiple vulnerabi... File : google_chrome_15_0_874_120.nasl - Type : ACT_GATHER_INFO |
2010-12-08 | Name : The remote FreeBSD host is missing a security-related update. File : freebsd_pkg_6887828f022911e0b84d00262d5ed8ee.nasl - Type : ACT_GATHER_INFO |
Alert History
Date | Informations |
---|---|
2014-02-17 11:31:04 |
|
2013-09-20 17:21:19 |
|