Mehrere Probleme in libav
ID: | USN-2944-1 |
Distribution: | Ubuntu |
Plattformen: | Ubuntu 12.04 LTS |
Datum: | Di, 5. April 2016, 07:22 |
Referenzen: | http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-1898
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2330 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-3395 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-8365 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-8364 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-6826 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-6820 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1872 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-6824 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8541 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-1897 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-6818 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2326 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-5479 |
Applikationen: | libav |
Originalnachricht |
|
This is an OpenPGP/MIME signed message (RFC 4880 and 3156) --===============8937227499923154163== Content-Type: multipart/signed; micalg=pgp-sha512; protocol="application/pgp-signature"; boundary="TGfPOkXTWESva44Xb0pjeG6Gc1Jf67NdJ" This is an OpenPGP/MIME signed message (RFC 4880 and 3156) --TGfPOkXTWESva44Xb0pjeG6Gc1Jf67NdJ Content-Type: text/plain; charset=utf- Content-Transfer-Encoding: quoted-printable ========================================================================== Ubuntu Security Notice USN-2944-1 April 04, 2016 libav vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 12.04 LTS Summary: Libav could be made to crash or run programs as your login if it opened a specially crafted file. Software Description: - libav: Multimedia player, server, encoder and transcoder Details: It was discovered that Libav incorrectly handled certain malformed media files. If a user were tricked into opening a crafted media file, an attacker could cause a denial of service via application crash, or possibly execute arbitrary code with the privileges of the user invoking the program. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 12.04 LTS: libavcodec53 4:0.8.17-0ubuntu0.12.04.2 libavformat53 4:0.8.17-0ubuntu0.12.04.2 In general, a standard system update will make all the necessary changes. References: http://www.ubuntu.com/usn/usn-2944-1 CVE-2014-8541, CVE-2015-1872, CVE-2015-3395, CVE-2015-5479, CVE-2015-6818, CVE-2015-6820, CVE-2015-6824, CVE-2015-6826, CVE-2015-8364, CVE-2015-8365, CVE-2016-1897, CVE-2016-1898, CVE-2016-2326, CVE-2016-2330 Package Information: https://launchpad.net/ubuntu/+source/libav/4:0.8.17-0ubuntu0.12.04.2 --TGfPOkXTWESva44Xb0pjeG6Gc1Jf67NdJ Content-Type: application/pgp-signature; name="signature.asc" Content-Description: OpenPGP digital signature Content-Disposition: attachment; filename="signature.asc" -----BEGIN PGP SIGNATURE----- Version: GnuPG v2 iQIcBAEBCgAGBQJXAroyAAoJEGVp2FWnRL6TP84P/2dJT5JLWF2M4X7H8fuHgXpu bz6E3mWmRZqabxfm8FNQ7T/yw20f9AbmXpaPpTdZ721fInTbv7L+s/GN5IkiSepY 2rVdA1CeL45yr7A3ijDdfZYfF0c/Z+3PjUHXnQN58SSLWxgDMdNWI/ygvwxxeyjZ +ZqMuYyfPaUYFEI8s8BSVcThHm5sd+32HNQrsxDr0l+A7P8d6tO6LuHMFKu7pKQg BsX4MGs2ZLm19YjtAnW6DFYCz3neHQch0ZsB6bCgmFMGuBNLA3B5/XHYIGSEwFzI 2x0rPXVBjRqXYkeym4UFbIpLwAZdSoYZKuagdOgPDvl6OWY9ClmM3CkMCsZ3rhD6 AzL+Nnj7E/JFSozUAIkNoA8LNaNd9sTQl16HpebLN6plZKCakfv7w7sflrfSH401 XgFMEuAv20IlQhhUniMW8BJZlk4r9BsiKnq+nG1ZkGp+bXYTSCnlbA5Yyb/b7L/X 1oJyMwdsakWDnT8z9w45VAgp5WItwkkA+/i7PHZU+2Pxh0pKEVGPS1/t+ErONWim uILHdq4zYEXDfvEkfnLrzxR4mozGtYin4flO5nA52SMITACDVs+viL6jgPCY6mA2 4FtgQ4fqe7TgzTtaJtjiNwbs6J/Rc0OWxvqDbtIlmxkDFersllIvP1/g9Dbkt8La BWTkkJUsWYzEu/NC50eH =Pzd8 -----END PGP SIGNATURE----- --TGfPOkXTWESva44Xb0pjeG6Gc1Jf67NdJ-- --===============8937227499923154163== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline -- ubuntu-security-announce mailing list ubuntu-security-announce@lists.ubuntu.com Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-security-announce --===============8937227499923154163==-- |