Bugzilla – Bug 957116
VUL-0: CVE-2015-8365: libav, ffmpeg: out of array access / asan_heap-oob
Last modified: 2018-07-18 14:43:30 UTC
CVE-2015-8365 http://git.videolan.org/?p=ffmpeg.git;a=commit;h=4a9af07a49295e014b059c1ab624c40345af5892 avcodec/smacker: Check that the data size is a multiple of a sample vector Fixes out of array access Fixes: ce19e41f0ef1e52a23edc488faecdb58/asan_heap-oob_2504e97_4202_ffa0df1baed14022b9bfd4f8ac23d0cb.smk Found-by: Mateusz "j00ru" Jurczyk and Gynvael Coldwind Signed-off-by: Michael Niedermayer <michael@niedermayer.cc> References: http://people.canonical.com/~ubuntu-security/cve/2015/CVE-2015-8365.html
Jan, Martin: Could you take this bug and apply these patches or upgrade to a unaffected version?
bugbot adjusting priority
This is an autogenerated message for OBS integration: This bug (957116) was mentioned in https://build.opensuse.org/request/show/347766 Factory / ffmpeg
This is an autogenerated message for OBS integration: This bug (957116) was mentioned in https://build.opensuse.org/request/show/348011 Factory / ffmpeg
This is an autogenerated message for OBS integration: This bug (957116) was mentioned in https://build.opensuse.org/request/show/349562 42.1 / ffmpeg
thanks Jan, update is running
Releasing openSUSE Leap 42.1 Update
openSUSE-SU-2015:2370-1: An update that fixes three vulnerabilities is now available. Category: security (moderate) Bug References: 957114,957115,957116 CVE References: CVE-2015-8363,CVE-2015-8364,CVE-2015-8365 Sources used: openSUSE Leap 42.1 (src): ffmpeg-2.8.3-6.1
This is an autogenerated message for OBS integration: This bug (957116) was mentioned in https://build.opensuse.org/request/show/623663 15.0+42.3+Backports:SLE-12-SP2 / chromium+codec2+ffmpeg-2+ffmpeg-3+ffmpeg-4+libsodium+libvpx-1_6+zeromq