Bugzilla – Bug 957114
VUL-0: CVE-2015-8363: libav, ffmpeg: Check for duplicate SIZ marker / asan_heap-oob
Last modified: 2018-07-18 14:43:21 UTC
CVE-2015-8363 http://git.videolan.org/?p=ffmpeg.git;a=commit;h=44a7f17d0b20e6f8d836b2957e3e357b639f19a2 avcodec/jpeg2000dec: Check for duplicate SIZ marker Fixes: 0231a17345734228011c6f35a64e4594/asan_heap-oob_1d92a72_3218_1213809a9e3affec77e4c191fdfdc0a9.mov Found-by: Mateusz "j00ru" Jurczyk and Gynvael Coldwind Signed-off-by: Michael Niedermayer <michael@niedermayer.cc> References: http://people.canonical.com/~ubuntu-security/cve/2015/CVE-2015-8363.html
Jan, Martin: Could you take this bug and apply these patches or upgrade to a unaffected version?
bugbot adjusting priority
This is an autogenerated message for OBS integration: This bug (957114) was mentioned in https://build.opensuse.org/request/show/347766 Factory / ffmpeg
This is an autogenerated message for OBS integration: This bug (957114) was mentioned in https://build.opensuse.org/request/show/348011 Factory / ffmpeg
This is an autogenerated message for OBS integration: This bug (957114) was mentioned in https://build.opensuse.org/request/show/349562 42.1 / ffmpeg
thanks Jan, update is running
Releasing openSUSE Leap 42.1 Update
openSUSE-SU-2015:2370-1: An update that fixes three vulnerabilities is now available. Category: security (moderate) Bug References: 957114,957115,957116 CVE References: CVE-2015-8363,CVE-2015-8364,CVE-2015-8365 Sources used: openSUSE Leap 42.1 (src): ffmpeg-2.8.3-6.1
This is an autogenerated message for OBS integration: This bug (957114) was mentioned in https://build.opensuse.org/request/show/623663 15.0+42.3+Backports:SLE-12-SP2 / chromium+codec2+ffmpeg-2+ffmpeg-3+ffmpeg-4+libsodium+libvpx-1_6+zeromq