Bug 57715 - ffmpeg: Multiple issues (5.0)
Summary: ffmpeg: Multiple issues (5.0)
Status: CLOSED FIXED
Alias: None
Product: UCS
Classification: Unclassified
Component: Security updates
Version: UCS 5.0
Hardware: All Linux
: P3 normal
Target Milestone: UCS 5.0-9-errata
Assignee: Quality Assurance
QA Contact: Iván.Delgado
URL:
Keywords:
: 57717 (view as bug list)
Depends on:
Blocks:
 
Reported: 2024-11-04 11:12 CET by Quality Assurance
Modified: 2024-11-06 18:15 CET (History)
0 users

See Also:
What kind of report is it?: Security Issue
What type of bug is this?: ---
Who will be affected by this bug?: ---
How will those affected feel about the bug?: ---
User Pain:
Enterprise Customer affected?:
School Customer affected?:
ISV affected?:
Waiting Support:
Flags outvoted (downgraded) after PO Review:
Ticket number:
Bug group (optional):
Customer ID:
Max CVSS v3 score: 8.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H) NVD


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Quality Assurance univentionstaff 2024-11-04 11:12:21 CET
New Debian ffmpeg 7:4.1.11-0+deb10u2 fixes:
This update addresses the following issues:
7:4.1.11-0+deb10u2 (Mon, 28 Oct 2024 22:16:34 +0200)
* Non-maintainer upload by the ELTS Team.
* CVE-2020-20898: avfilter/vf_convolution integer overflow
* CVE-2020-22040: avfilter/f_reverse memory leaks
* CVE-2020-22051: avfilter/vf_tile memory leak
* CVE-2020-22056: avfilter/af_acrossover memory leak
* CVE-2021-38090: avfilter/vf_convolution integer overflow
* CVE-2021-38091: avfilter/vf_convolution integer overflow
* CVE-2021-38092: avfilter/vf_convolution integer overflow
* CVE-2021-38093: avfilter/vf_convolution integer overflow
* CVE-2021-38094: avfilter/vf_convolution integer overflow
* CVE-2022-48434: lavc/pthread_frame hwaccel use-after-free
* CVE-2023-49502: avfilter/bwdif buffer overflow
* CVE-2023-50010: avfilter/vf_gradfun buffer overflow
* CVE-2023-51793: avfilter/vf_weave buffer overflow
* CVE-2023-51794: avfilter/af_stereowiden buffer overflow
* CVE-2023-51798: avfilter/vf_minterpolate floating point exception
* CVE-2024-31578: avutil/hwcontext use-after-free
* CVE-2024-32230: avcodec/mpegvideo_enc buffer overflow
Comment 1 Iván.Delgado univentionstaff 2024-11-04 11:35:56 CET
*** Bug 57717 has been marked as a duplicate of this bug. ***
Comment 2 Quality Assurance univentionstaff 2024-11-04 12:00:08 CET
--- mirror/ftp/pool/main/f/ffmpeg/ffmpeg_4.1.11-0+deb10u1.dsc
+++ apt/ucs_5.0-0-errata5.0-9/source/ffmpeg_4.1.11-0+deb10u2.dsc
@@ -1,3 +1,24 @@
+7:4.1.11-0+deb10u2 [Mon, 28 Oct 2024 22:16:34 +0200] Adrian Bunk <bunk@debian.org>:
+
+  * Non-maintainer upload by the ELTS Team.
+  * CVE-2020-20898: avfilter/vf_convolution integer overflow
+  * CVE-2020-22040: avfilter/f_reverse memory leaks
+  * CVE-2020-22051: avfilter/vf_tile memory leak
+  * CVE-2020-22056: avfilter/af_acrossover memory leak
+  * CVE-2021-38090: avfilter/vf_convolution integer overflow
+  * CVE-2021-38091: avfilter/vf_convolution integer overflow
+  * CVE-2021-38092: avfilter/vf_convolution integer overflow
+  * CVE-2021-38093: avfilter/vf_convolution integer overflow
+  * CVE-2021-38094: avfilter/vf_convolution integer overflow
+  * CVE-2022-48434: lavc/pthread_frame hwaccel use-after-free
+  * CVE-2023-49502: avfilter/bwdif buffer overflow
+  * CVE-2023-50010: avfilter/vf_gradfun buffer overflow
+  * CVE-2023-51793: avfilter/vf_weave buffer overflow
+  * CVE-2023-51794: avfilter/af_stereowiden buffer overflow
+  * CVE-2023-51798: avfilter/vf_minterpolate floating point exception
+  * CVE-2024-31578: avutil/hwcontext use-after-free
+  * CVE-2024-32230: avcodec/mpegvideo_enc buffer overflow
+
 7:4.1.11-0+deb10u1 [Tue, 13 Jun 2023 10:16:38 +0200] Sylvain Beucler <beuc@debian.org>:
 
   * Non-maintainer upload by the LTS Security Team.

<http://piuparts.knut.univention.de/5.0-9/#6410630230805900252>
Comment 3 Iván.Delgado univentionstaff 2024-11-05 16:02:18 CET
OK: bug
OK: yaml
OK: announce_errata
OK: patch
~OK: piuparts
   Freexian ships dbgsym packages

[5.0-9] 282bc59f8e Revert "Bug #57715: ffmpeg 7:4.1.11-0+deb10u2"
 doc/errata/staging/ffmpeg.yaml | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

[5.0-9] a9beca3b78 Bug #57715: ffmpeg 7:4.1.11-0+deb10u2
 doc/errata/staging/ffmpeg.yaml | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

[5.0-9] 159291ec66 Bug #57715: ffmpeg 7:4.1.11-0+deb10u2
 doc/errata/staging/ffmpeg.yaml | 40 ++++++++++++++++++++++++++++++++++++++++
 1 file changed, 40 insertions(+)