Get the LinuxSecurity news you want faster with RSS
Powered By
Pardus: 2011-87: ffmpeg: Code Execution
Posted by Benjamin D. Thomas
A vulnerability has been fixed in ffmpeg, which can be result in an out of array write and potentially arbitrary code execution.
------------------------------------------------------------------------
Pardus Linux Security Advisory 2011-87 security@pardus.org.tr
------------------------------------------------------------------------
Date: 2011-06-21
Type: Local
------------------------------------------------------------------------
Summary
======
A vulnerability has been fixed in ffmpeg, which can be result in an out
of array write and potentially arbitrary code execution.
Description
==========
CVE-2011-1931:
ffmpeg/libav out of array write in AMV parsing
Affected packages:
Pardus 2009:
ffmpeg, all before 0.6.1_20110105-90-42
mplayer, all before 0.0_20110105-140-38
Resolution
=========
There are update(s) for ffmpeg, mplayer. You can update them via Package
Manager or with a single command from console:
pisi up ffmpeg mplayer
References
=========
* http://bugs.debian.org/cgi-bin/bugreport.cgi?bugb4339
* http://seclists.org/bugtraq/2011/Apr/257
* http://git.videolan.org/?p˙mpeg.gi...626fa0eda61a32
* http://bugs.pardus.org.tr/show_bug.cgi?id181
------------------------------------------------------------------------