Bug 1133155 (CVE-2019-11338) - VUL-0: CVE-2019-11338: ffmpeg-4: libavcodec/hevcdec.c in FFmpeg 4.1.2 mishandles detection of duplicate first slices, which allows remote attackers to cause a denial of service (NULL pointer dereference and out-of-array access) or possibly ha
Summary: VUL-0: CVE-2019-11338: ffmpeg-4: libavcodec/hevcdec.c in FFmpeg 4.1.2 mishand...
Status: RESOLVED FIXED
Alias: CVE-2019-11338
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Major
Target Milestone: ---
Assignee: E-mail List
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/229995/
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2019-04-23 16:01 UTC by Marcus Meissner
Modified: 2024-04-22 17:15 UTC (History)
3 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Marcus Meissner 2019-04-23 16:01:18 UTC
CVE-2019-11338

libavcodec/hevcdec.c in FFmpeg 4.1.2 mishandles detection of duplicate first
slices, which allows remote attackers to cause a denial of service (NULL pointer
dereference and out-of-array access) or possibly have unspecified other impact
via crafted HEVC data.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2019-11338
http://people.canonical.com/~ubuntu-security/cve/2019/CVE-2019-11338.html
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-11338
https://github.com/FFmpeg/FFmpeg/commit/54655623a82632e7624714d7b2a3e039dc5faa7e
Comment 1 Jan Engelhardt 2019-05-01 08:59:56 UTC
This affected component is not built and not included in openSUSE.
Comment 2 Swamp Workflow Management 2019-12-12 16:20:18 UTC
This is an autogenerated message for OBS integration:
This bug (1133155) was mentioned in
https://build.opensuse.org/request/show/756103 15.1+Backports:SLE-12-SP2+Backports:SLE-15+Backports:SLE-15-SP1 / ffmpeg-4
Comment 3 Swamp Workflow Management 2019-12-14 07:30:22 UTC
This is an autogenerated message for OBS integration:
This bug (1133155) was mentioned in
https://build.opensuse.org/request/show/756985 15.1+Backports:SLE-12-SP2+Backports:SLE-15+Backports:SLE-15-SP1 / ffmpeg-4
Comment 4 Swamp Workflow Management 2020-01-13 23:13:27 UTC
openSUSE-SU-2020:0024-1: An update that fixes 5 vulnerabilities is now available.

Category: security (moderate)
Bug References: 1100345,1133123,1133153,1133155,1149839
CVE References: CVE-2017-17555,CVE-2018-13305,CVE-2019-11338,CVE-2019-11339,CVE-2019-15942
Sources used:
SUSE Package Hub for SUSE Linux Enterprise 12 (src):    ffmpeg-4-4.0.5-17.1
Comment 5 Swamp Workflow Management 2020-01-13 23:18:05 UTC
openSUSE-SU-2020:0024-1: An update that fixes 5 vulnerabilities is now available.

Category: security (moderate)
Bug References: 1100345,1133123,1133153,1133155,1149839
CVE References: CVE-2017-17555,CVE-2018-13305,CVE-2019-11338,CVE-2019-11339,CVE-2019-15942
Sources used:
openSUSE Leap 15.1 (src):    ffmpeg-4-4.2.1-lp151.2.3.1
openSUSE Backports SLE-15-SP1 (src):    ffmpeg-4-4.2.1-bp151.5.3.1
openSUSE Backports SLE-15 (src):    ffmpeg-4-4.2.1-bp150.24.1
SUSE Package Hub for SUSE Linux Enterprise 12 (src):    ffmpeg-4-4.0.5-17.1
Comment 7 OBSbugzilla Bot 2024-04-22 14:25:43 UTC
This is an autogenerated message for OBS integration:
This bug (1133155) was mentioned in
https://build.opensuse.org/request/show/1169676 Backports:SLE-15-SP5 / ffmpeg-4
Comment 8 OBSbugzilla Bot 2024-04-22 17:15:45 UTC
This is an autogenerated message for OBS integration:
This bug (1133155) was mentioned in
https://build.opensuse.org/request/show/1169721 Backports:SLE-15-SP5 / ffmpeg-4