Bug 1105869 (CVE-2018-15822) - VUL-1: CVE-2018-15822: ffmpeg: The flv_write_packet function in libavformat/flvenc.c in FFmpeg through 4.0.2does not check for an empty audio packet, leading to an assertion failure.
Summary: VUL-1: CVE-2018-15822: ffmpeg: The flv_write_packet function in libavformat/f...
Status: RESOLVED FIXED
Alias: CVE-2018-15822
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P4 - Low : Minor
Target Milestone: ---
Assignee: Security Team bot
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/213258/
Whiteboard: CVSSv3:SUSE:CVE-2018-15822:5.5:(AV:L/...
Keywords:
Depends on:
Blocks:
 
Reported: 2018-08-24 05:29 UTC by Marcus Meissner
Modified: 2024-04-22 17:15 UTC (History)
5 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Marcus Meissner 2018-08-24 05:29:11 UTC
CVE-2018-15822

The flv_write_packet function in libavformat/flvenc.c in FFmpeg through 4.0.2
does not check for an empty audio packet, leading to an assertion failure.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2018-15822
https://github.com/FFmpeg/FFmpeg/commit/6b67d7f05918f7a1ee8fc6ff21355d7e8736aa10
Comment 2 Swamp Workflow Management 2018-09-13 09:20:11 UTC
This is an autogenerated message for OBS integration:
This bug (1105869) was mentioned in
https://build.opensuse.org/request/show/635494 15.0+42.3+Backports:SLE-12-SP2+Backports:SLE-15 / ffmpeg-4
Comment 4 Swamp Workflow Management 2018-09-15 13:08:49 UTC
openSUSE-SU-2018:2723-1: An update that solves two vulnerabilities and has one errata is now available.

Category: security (low)
Bug References: 1092241,1100348,1105869
CVE References: CVE-2018-13300,CVE-2018-15822
Sources used:
openSUSE Leap 42.3 (src):    ffmpeg-4-4.0.2-13.1
openSUSE Leap 15.0 (src):    ffmpeg-4-4.0.2-lp150.13.1
Comment 5 Swamp Workflow Management 2018-09-15 13:14:35 UTC
openSUSE-SU-2018:2734-1: An update that solves two vulnerabilities and has one errata is now available.

Category: security (low)
Bug References: 1092241,1100348,1105869
CVE References: CVE-2018-13300,CVE-2018-15822
Sources used:
SUSE Package Hub for SUSE Linux Enterprise 12 (src):    ffmpeg-4-4.0.2-13.1
Comment 8 Swamp Workflow Management 2018-09-22 07:31:33 UTC
openSUSE-SU-2018:2723-2: An update that solves two vulnerabilities and has one errata is now available.

Category: security (low)
Bug References: 1092241,1100348,1105869
CVE References: CVE-2018-13300,CVE-2018-15822
Sources used:
openSUSE Backports SLE-15 (src):    ffmpeg-4-4.0.2-bp150.3.3.1
Comment 13 Swamp Workflow Management 2018-11-02 20:11:16 UTC
SUSE-SU-2018:3609-1: An update that fixes four vulnerabilities is now available.

Category: security (moderate)
Bug References: 1097983,1100345,1100348,1105869
CVE References: CVE-2018-12458,CVE-2018-13300,CVE-2018-13305,CVE-2018-15822
Sources used:
SUSE Linux Enterprise Workstation Extension 15 (src):    ffmpeg-3.4.2-4.12.4
SUSE Linux Enterprise Module for Packagehub Subpackages 15 (src):    ffmpeg-3.4.2-4.12.4
SUSE Linux Enterprise Module for Open Buildservice Development Tools 15 (src):    ffmpeg-3.4.2-4.12.4
SUSE Linux Enterprise Module for Desktop Applications 15 (src):    ffmpeg-3.4.2-4.12.4
Comment 14 Marcus Meissner 2018-11-09 07:19:15 UTC
done
Comment 15 Swamp Workflow Management 2019-03-28 17:14:40 UTC
openSUSE-SU-2019:1066-1: An update that solves two vulnerabilities and has one errata is now available.

Category: security (low)
Bug References: 1092241,1100348,1105869
CVE References: CVE-2018-13300,CVE-2018-15822
Sources used:
openSUSE Backports SLE-15 (src):    ffmpeg-4-4.0.2-bp150.21.1

*** NOTE: This information is not intended to be used for external
    communication, because this may only be a partial fix.
    If you have questions please reach out to maintenance coordination.
Comment 17 OBSbugzilla Bot 2024-04-22 14:25:40 UTC
This is an autogenerated message for OBS integration:
This bug (1105869) was mentioned in
https://build.opensuse.org/request/show/1169676 Backports:SLE-15-SP5 / ffmpeg-4
Comment 18 OBSbugzilla Bot 2024-04-22 17:15:40 UTC
This is an autogenerated message for OBS integration:
This bug (1105869) was mentioned in
https://build.opensuse.org/request/show/1169721 Backports:SLE-15-SP5 / ffmpeg-4