Bug 1034575 (CVE-2015-8270) - [multimedia:libs]: CVE-2015-8270 CVE-2015-8271 CVE-2015-8272: RTMPDump 2.4 allows remote attackers to trigger a denial of service (NULLpointer dereference and pr...
Summary: [multimedia:libs]: CVE-2015-8270 CVE-2015-8271 CVE-2015-8272: RTMPDump 2.4 al...
Status: RESOLVED WONTFIX
Alias: CVE-2015-8270
Product: openSUSE Distribution
Classification: openSUSE
Component: Basesystem (show other bugs)
Version: Leap 42.2
Hardware: Other Other
: P5 - None : Normal (vote)
Target Milestone: ---
Assignee: Dominique Leuenberger
QA Contact: E-mail List
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2017-04-18 08:04 UTC by Marcus Meissner
Modified: 2017-06-23 12:35 UTC (History)
2 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Comment 1 Marcus Meissner 2017-04-18 08:12:37 UTC
also:

http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2015-8271

The AMF3CD_AddProp function in amf.c in RTMPDump 2.4 allows remote RTMP Media
servers to execute arbitrary code.
Comment 2 Marcus Meissner 2017-04-18 08:13:12 UTC
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2015-8270

The AMF3ReadString function in amf.c in RTMPDump 2.4 allows remote RTMP Media
servers to cause a denial of service (invalid pointer dereference and process
crash).
Comment 3 Dominique Leuenberger 2017-05-23 12:52:02 UTC
Olaf: is rtmpdump needed in any way by your packages as a dependency?

This project is dead upstream and considering CVEs to start pop up, I'd actually go the course of removing this from multimedia:libs - unless something of yours depends on it (e.g. ffmpeg)
Comment 4 Olaf Hering 2017-05-23 13:28:12 UTC
ffmpeg can optionally link to rtmpdump. Not sure if anyone would miss the functionality.
Comment 5 Olaf Hering 2017-06-02 07:57:48 UTC
rtmpdump is now detached. Feel free to drop it from OBS.
Comment 6 Bjørn Lie 2017-06-02 18:00:36 UTC
rtmpdump BR in gstreamer-plugins-ugly dropped (orig-addon part)

See sr#500759
Comment 7 Dominique Leuenberger 2017-06-23 12:35:49 UTC
multimedia:libs/rtmpdump has been removed