Bugzilla – Bug 1149839
VUL-1: CVE-2019-15942: ffmpeg,ffmpeg-4: Conditional jump or move depends on uninitialised value" issue in h2645_parse
Last modified: 2024-04-22 17:15:47 UTC
CVE-2019-15942 FFmpeg through 4.2 has a "Conditional jump or move depends on uninitialised value" issue in h2645_parse because alloc_rbsp_buffer in libavcodec/h2645_parse.c mishandles rbsp_buffer. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2019-15942 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-15942 https://trac.ffmpeg.org/ticket/8093
The issue introduced in version 4.2 at commit [1]. A POC can be found at [2]. SLE15 ships version 3.4.2. Leap 15.0 and Leap 15.1 are not affected they ship version 4.0.2. TW is affected ships version 4.2. [1] https://github.com/FFmpeg/FFmpeg/commit/992532ee3122d7938a7581988eea401b57de8189 [2] https://trac.ffmpeg.org/ticket/8093
This is an autogenerated message for OBS integration: This bug (1149839) was mentioned in https://build.opensuse.org/request/show/729720 Factory / ffmpeg-4
This is an autogenerated message for OBS integration: This bug (1149839) was mentioned in https://build.opensuse.org/request/show/756103 15.1+Backports:SLE-12-SP2+Backports:SLE-15+Backports:SLE-15-SP1 / ffmpeg-4
This is an autogenerated message for OBS integration: This bug (1149839) was mentioned in https://build.opensuse.org/request/show/756985 15.1+Backports:SLE-12-SP2+Backports:SLE-15+Backports:SLE-15-SP1 / ffmpeg-4
openSUSE-SU-2020:0024-1: An update that fixes 5 vulnerabilities is now available. Category: security (moderate) Bug References: 1100345,1133123,1133153,1133155,1149839 CVE References: CVE-2017-17555,CVE-2018-13305,CVE-2019-11338,CVE-2019-11339,CVE-2019-15942 Sources used: SUSE Package Hub for SUSE Linux Enterprise 12 (src): ffmpeg-4-4.0.5-17.1
openSUSE-SU-2020:0024-1: An update that fixes 5 vulnerabilities is now available. Category: security (moderate) Bug References: 1100345,1133123,1133153,1133155,1149839 CVE References: CVE-2017-17555,CVE-2018-13305,CVE-2019-11338,CVE-2019-11339,CVE-2019-15942 Sources used: openSUSE Leap 15.1 (src): ffmpeg-4-4.2.1-lp151.2.3.1 openSUSE Backports SLE-15-SP1 (src): ffmpeg-4-4.2.1-bp151.5.3.1 openSUSE Backports SLE-15 (src): ffmpeg-4-4.2.1-bp150.24.1 SUSE Package Hub for SUSE Linux Enterprise 12 (src): ffmpeg-4-4.0.5-17.1
Done
This is an autogenerated message for OBS integration: This bug (1149839) was mentioned in https://build.opensuse.org/request/show/1169676 Backports:SLE-15-SP5 / ffmpeg-4
This is an autogenerated message for OBS integration: This bug (1149839) was mentioned in https://build.opensuse.org/request/show/1169721 Backports:SLE-15-SP5 / ffmpeg-4