PublicDateAtUSN: 2011-11-25 Candidate: CVE-2011-4352 PublicDate: 2012-08-20 20:55:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4352 http://www.securityfocus.com/archive/1/520622 https://ubuntu.com/security/notices/USN-1320-1 https://ubuntu.com/security/notices/USN-1333-1 Description: Integer overflow in the vp3_dequant function in the VP3 decoder (vp3.c) in libavcodec in FFmpeg 0.5.x before 0.5.7, 0.6.x before 0.6.4, 0.7.x before 0.7.9, and 0.8.x before 0.8.8; and in Libav 0.5.x before 0.5.6, 0.6.x before 0.6.4, and 0.7.x before 0.7.3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted VP3 stream, which triggers a buffer overflow. Ubuntu-Description: Notes: mdeslaur> ffmpeg-extra in multiverse needs to have matching version mdeslaur> libav-extra is built with tarball produced by libav package mdeslaur> libav doesn't seem to have equivalent patch yet as of 2012-12-22 mdeslaur> See thread: http://thread.gmane.org/gmane.comp.video.libav.devel/15121 mdeslaur> this fixes NGS00145 Bugs: Priority: medium Discovered-by: Phillip Langlois Assigned-to: mdeslaur CVSS: Patches_ffmpeg: upstream: http://git.videolan.org/?p=ffmpeg.git;a=commit;h=eef5c35b4352ec49ca41f6198bee8a976b1f81e5 upstream_ffmpeg: needs-triage hardy_ffmpeg: ignored (reached end-of-life) lucid_ffmpeg: not-affected (code not present) maverick_ffmpeg: released (4:0.6-2ubuntu6.3) natty_ffmpeg: DNE oneiric_ffmpeg: DNE devel_ffmpeg: DNE Patches_ffmpeg-extra: upstream_ffmpeg-extra: needs-triage hardy_ffmpeg-extra: DNE lucid_ffmpeg-extra: not-affected (code not present) maverick_ffmpeg-extra: released (4:0.6-2ubuntu3.3) natty_ffmpeg-extra: DNE oneiric_ffmpeg-extra: DNE devel_ffmpeg-extra: DNE Patches_libav: upstream: http://git.libav.org/?p=libav.git;a=commit;h=8b94df0f2047e9728cb872adc9e64557b7a5152f upstream_libav: released (0.7.3) hardy_libav: DNE lucid_libav: DNE maverick_libav: DNE natty_libav: released (4:0.6.4-0ubuntu0.11.04.1) oneiric_libav: released (4:0.7.3-0ubuntu0.11.10.1) devel_libav: not-affected (4:0.7.3-2ubuntu1) Patches_libav-extra: upstream_libav-extra: needs-triage hardy_libav-extra: DNE lucid_libav-extra: DNE maverick_libav-extra: DNE natty_libav-extra: released (4:0.6.4-1ubuntu1) oneiric_libav-extra: released (4:0.7.3ubuntu0.11.10.1) devel_libav-extra: not-affected (4:0.7.3ubuntu1)