DSA-2378-1 ffmpeg -- several vulnerabilities

Related Vulnerabilities: CVE-2011-4351   CVE-2011-4353   CVE-2011-4364   CVE-2011-4579  

Several vulnerabilities have been discovered in FFmpeg, a multimedia player, server and encoder. Multiple input validations in the decoders for QDM2, VP5, VP6, VMD and SVQ1 files could lead to the execution of arbitrary code. For the stable distribution (squeeze), this problem has been fixed in version 4:0.5.6-3. For the unstable distribution (sid), this problem has been fixed in version 4:0.7.3-1 of the libav source package. We recommend that you upgrade your ffmpeg packages.

Debian Security Advisory

DSA-2378-1 ffmpeg -- several vulnerabilities

Date Reported:
03 Jan 2012
Affected Packages:
ffmpeg
Vulnerable:
Yes
Security database references:
In Mitre's CVE dictionary: CVE-2011-4351, CVE-2011-4353, CVE-2011-4364, CVE-2011-4579.
More information:

Several vulnerabilities have been discovered in FFmpeg, a multimedia player, server and encoder. Multiple input validations in the decoders for QDM2, VP5, VP6, VMD and SVQ1 files could lead to the execution of arbitrary code.

For the stable distribution (squeeze), this problem has been fixed in version 4:0.5.6-3.

For the unstable distribution (sid), this problem has been fixed in version 4:0.7.3-1 of the libav source package.

We recommend that you upgrade your ffmpeg packages.