Login
Newsletter
Werbung

Sicherheit: Mehrere Probleme in FFmpeg
Aktuelle Meldungen Distributionen
Name: Mehrere Probleme in FFmpeg
ID: USN-3967-1
Distribution: Ubuntu
Plattformen: Ubuntu 18.04 LTS, Ubuntu 18.10, Ubuntu 19.04
Datum: Mo, 6. Mai 2019, 21:04
Referenzen: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-11339
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-11338
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-9718
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-15822
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-9721
Applikationen: FFmpeg

Originalnachricht


--===============4888617943328262097==
Content-Type: multipart/signed; micalg="pgp-sha512";
protocol="application/pgp-signature";
boundary="=-nmLsQl81Xm+4Tp19fIJc"


--=-nmLsQl81Xm+4Tp19fIJc
Content-Type: text/plain; charset="UTF-8
Content-Transfer-Encoding: quoted-printable

=======================================================================
===
Ubuntu Security Notice USN-3967-1
May 06, 2019

FFmpeg vulnerabilities
=======================================================================
===

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 19.04
- Ubuntu 18.10
- Ubuntu 18.04 LTS

Summary:

FFmpeg could be made to crash if it opened a specially crafted
file.

Software Description:
- ffmpeg: Tools for transcoding, streaming and playing of multimedia
files

Details:

It was discovered that FFmpeg contained multiple security issues when
handling
certain multimedia files. If a user were tricked into opening a crafted
multimedia file, an attacker could cause a denial of service via
application
crash.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 19.04:
ffmpeg 7:4.1.3-0ubuntu1
libavcodec-extra58 7:4.1.3-0ubuntu1
libavcodec58 7:4.1.3-0ubuntu1
libavdevice58 7:4.1.3-0ubuntu1
libavfilter-extra7 7:4.1.3-0ubuntu1
libavfilter7 7:4.1.3-0ubuntu1
libavformat58 7:4.1.3-0ubuntu1
libavresample4 7:4.1.3-0ubuntu1
libavutil56 7:4.1.3-0ubuntu1
libpostproc55 7:4.1.3-0ubuntu1
libswresample3 7:4.1.3-0ubuntu1
libswscale5 7:4.1.3-0ubuntu1

Ubuntu 18.10:
ffmpeg 7:4.0.4-0ubuntu1
libavcodec-extra58 7:4.0.4-0ubuntu1
libavcodec58 7:4.0.4-0ubuntu1
libavdevice58 7:4.0.4-0ubuntu1
libavfilter-extra7 7:4.0.4-0ubuntu1
libavfilter7 7:4.0.4-0ubuntu1
libavformat58 7:4.0.4-0ubuntu1
libavresample4 7:4.0.4-0ubuntu1
libavutil56 7:4.0.4-0ubuntu1
libpostproc55 7:4.0.4-0ubuntu1
libswresample3 7:4.0.4-0ubuntu1
libswscale5 7:4.0.4-0ubuntu1

Ubuntu 18.04 LTS:
ffmpeg 7:3.4.6-0ubuntu0.18.04.1
libavcodec-extra57 7:3.4.6-0ubuntu0.18.04.1
libavcodec57 7:3.4.6-0ubuntu0.18.04.1
libavdevice57 7:3.4.6-0ubuntu0.18.04.1
libavfilter-extra6 7:3.4.6-0ubuntu0.18.04.1
libavfilter6 7:3.4.6-0ubuntu0.18.04.1
libavformat57 7:3.4.6-0ubuntu0.18.04.1
libavresample3 7:3.4.6-0ubuntu0.18.04.1
libavutil55 7:3.4.6-0ubuntu0.18.04.1
libpostproc54 7:3.4.6-0ubuntu0.18.04.1
libswresample2 7:3.4.6-0ubuntu0.18.04.1
libswscale4 7:3.4.6-0ubuntu0.18.04.1

In general, a standard system update will make all the necessary
changes.

References:
https://usn.ubuntu.com/usn/usn-3967-1
CVE-2018-15822, CVE-2019-11338, CVE-2019-11339, CVE-2019-9718,
CVE-2019-9721

Package Information:
https://launchpad.net/ubuntu/+source/ffmpeg/7:4.1.3-0ubuntu1
https://launchpad.net/ubuntu/+source/ffmpeg/7:4.0.4-0ubuntu1
https://launchpad.net/ubuntu/+source/ffmpeg/7:3.4.6-0ubuntu0.18.04.1

--=-nmLsQl81Xm+4Tp19fIJc
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: This is a digitally signed message part
Content-Transfer-Encoding: 7bit

-----BEGIN PGP SIGNATURE-----

iQIzBAABCgAdFiEECtyyz6azUy6AZBzSkGeI6zGnN/8FAlzQd3YACgkQkGeI6zGn
N/93TRAAs8eb1h5JJd0ORsiEImBpO0LWPEqug3eg9doQKrUiI5vG9+MntSDn/2nd
XkgeXGEZtS/L0noft1X36KcwTjK1BGw1iTfLJ7kB2qXzs0FcYrxSjt43WAdjljKu
vAAJIs7eiwu3C5wItT4B78VNxYWoIo9DPISUa4PCStqkf9xAP04H8jTpX45Plzzr
5iZhJLvxZ/yHGscn9+/gEUpY8G5EQYSumwj/UpMI6YJRs5vEru/3pEMKEtiNIZdx
icBnqhejTe/aq5ZLKmzoFlyrQqjn29vF2GCyOGwpr+7rsklBgI4Ea3zLpfpf7Nqd
Q7U9n19AuUUk58HMUkrXf/HeRsFJn8XbdEUQiddEAKlnEGcoB8jxoBMuIgZ5VVs2
tJKBCQhK84aFDk/zaM+t15r50h3cml/XfCFXr4GjA/ywvu0KrbeBOs/CKxP3HGXF
CdvqPdxauQ51cBf2dT9XF/2JT992r4U7ypgAytyynszL+AsmDn1QnaQ8/wVsu9/T
vFPTjHtbWM1SnRaIUb6vP+0m0GH/Y7RcFe9qzks1vkpbax+/WhpFWWyAkdC55k4U
P86FCgJS1VKY8R+ToGtw8X6NcJIZdiErPUZnvfEjWdDKaH+/W79sSYjXojJ29Wo1
crGOkQIJ+P+OEdGpPWJYFkYimsl4QXamZI+eHzTWTRez6B9bIWw=
=JqPi
-----END PGP SIGNATURE-----

--=-nmLsQl81Xm+4Tp19fIJc--



--===============4888617943328262097==
Content-Type: text/plain; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: base64
Content-Disposition: inline

LS0gCnVidW50dS1zZWN1cml0eS1hbm5vdW5jZSBtYWlsaW5nIGxpc3QKdWJ1bnR1LXNlY3VyaXR5
LWFubm91bmNlQGxpc3RzLnVidW50dS5jb20KTW9kaWZ5IHNldHRpbmdzIG9yIHVuc3Vic2NyaWJl
IGF0OiBodHRwczovL2xpc3RzLnVidW50dS5jb20vbWFpbG1hbi9saXN0aW5mby91YnVudHUtc2Vj
dXJpdHktYW5ub3VuY2UK

--===============4888617943328262097==--
Pro-Linux
Pro-Linux @Facebook
Neue Nachrichten
Werbung