Bug 1149839 (CVE-2019-15942) - VUL-1: CVE-2019-15942: ffmpeg,ffmpeg-4: Conditional jump or move depends on uninitialised value" issue in h2645_parse
Summary: VUL-1: CVE-2019-15942: ffmpeg,ffmpeg-4: Conditional jump or move depends on u...
Status: RESOLVED FIXED
Alias: CVE-2019-15942
Product: openSUSE Tumbleweed
Classification: openSUSE
Component: Security (show other bugs)
Version: Current
Hardware: Other Other
: P4 - Low : Normal (vote)
Target Milestone: ---
Assignee: Security Team bot
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/241832/
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2019-09-06 15:05 UTC by Alexandros Toptsoglou
Modified: 2024-04-22 17:15 UTC (History)
0 users

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Alexandros Toptsoglou 2019-09-06 15:05:23 UTC
CVE-2019-15942

FFmpeg through 4.2 has a "Conditional jump or move depends on uninitialised
value" issue in h2645_parse because alloc_rbsp_buffer in
libavcodec/h2645_parse.c mishandles rbsp_buffer.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2019-15942
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-15942
https://trac.ffmpeg.org/ticket/8093
Comment 1 Alexandros Toptsoglou 2019-09-06 15:12:28 UTC
The issue introduced in version 4.2 at commit [1]. A POC can be found at [2].
SLE15 ships version 3.4.2. Leap 15.0 and Leap 15.1 are not affected they ship version 4.0.2. TW is affected ships version 4.2.

[1] https://github.com/FFmpeg/FFmpeg/commit/992532ee3122d7938a7581988eea401b57de8189
[2] https://trac.ffmpeg.org/ticket/8093
Comment 2 Swamp Workflow Management 2019-09-10 09:40:07 UTC
This is an autogenerated message for OBS integration:
This bug (1149839) was mentioned in
https://build.opensuse.org/request/show/729720 Factory / ffmpeg-4
Comment 3 Swamp Workflow Management 2019-12-12 16:20:21 UTC
This is an autogenerated message for OBS integration:
This bug (1149839) was mentioned in
https://build.opensuse.org/request/show/756103 15.1+Backports:SLE-12-SP2+Backports:SLE-15+Backports:SLE-15-SP1 / ffmpeg-4
Comment 4 Swamp Workflow Management 2019-12-14 07:30:26 UTC
This is an autogenerated message for OBS integration:
This bug (1149839) was mentioned in
https://build.opensuse.org/request/show/756985 15.1+Backports:SLE-12-SP2+Backports:SLE-15+Backports:SLE-15-SP1 / ffmpeg-4
Comment 5 Swamp Workflow Management 2020-01-13 23:13:34 UTC
openSUSE-SU-2020:0024-1: An update that fixes 5 vulnerabilities is now available.

Category: security (moderate)
Bug References: 1100345,1133123,1133153,1133155,1149839
CVE References: CVE-2017-17555,CVE-2018-13305,CVE-2019-11338,CVE-2019-11339,CVE-2019-15942
Sources used:
SUSE Package Hub for SUSE Linux Enterprise 12 (src):    ffmpeg-4-4.0.5-17.1
Comment 6 Swamp Workflow Management 2020-01-13 23:18:11 UTC
openSUSE-SU-2020:0024-1: An update that fixes 5 vulnerabilities is now available.

Category: security (moderate)
Bug References: 1100345,1133123,1133153,1133155,1149839
CVE References: CVE-2017-17555,CVE-2018-13305,CVE-2019-11338,CVE-2019-11339,CVE-2019-15942
Sources used:
openSUSE Leap 15.1 (src):    ffmpeg-4-4.2.1-lp151.2.3.1
openSUSE Backports SLE-15-SP1 (src):    ffmpeg-4-4.2.1-bp151.5.3.1
openSUSE Backports SLE-15 (src):    ffmpeg-4-4.2.1-bp150.24.1
SUSE Package Hub for SUSE Linux Enterprise 12 (src):    ffmpeg-4-4.0.5-17.1
Comment 7 Alexandros Toptsoglou 2020-05-12 11:26:39 UTC
Done
Comment 9 OBSbugzilla Bot 2024-04-22 14:25:44 UTC
This is an autogenerated message for OBS integration:
This bug (1149839) was mentioned in
https://build.opensuse.org/request/show/1169676 Backports:SLE-15-SP5 / ffmpeg-4
Comment 10 OBSbugzilla Bot 2024-04-22 17:15:47 UTC
This is an autogenerated message for OBS integration:
This bug (1149839) was mentioned in
https://build.opensuse.org/request/show/1169721 Backports:SLE-15-SP5 / ffmpeg-4