|
Family: Ubuntu Local Security Checks --> Category: infos
USN230-1 : ffmpeg vulnerability Vulnerability Scan
Vulnerability Scan Summary ffmpeg vulnerability
Detailed Explanation for this Vulnerability Test
Synopsis :
These remote packages are missing security patches :
- ffmpeg
- kino
- libavcodec-dev
- libavformat-dev
- libpostproc-dev
Description :
Simon Kilvington discovered a buffer overflow in the
avcodec_default_get_buffer() function of the ffmpeg library. By
tricking an user into opening a malicious movie which contains
specially crafted PNG images, this could be exploited to execute
arbitrary code with the user's rights.
Solution :
Upgrade to :
- ffmpeg-0.cvs20050121-1ubuntu1.1 (Ubuntu 5.04)
- kino-0.75-6ubuntu0.1 (Ubuntu 5.04)
- libavcodec-dev-0.cvs20050121-1ubuntu1.1 (Ubuntu 5.04)
- libavformat-dev-0.cvs20050121-1ubuntu1.1 (Ubuntu 5.04)
- libpostproc-dev-0.cvs20050121-1ubuntu1.1 (Ubuntu 5.04)
Threat Level: High
Click HERE for more information and discussions on this network vulnerability scan.
|