PublicDateAtUSN: 2012-09-10 Candidate: CVE-2012-2802 PublicDate: 2012-09-10 22:55:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2802 http://www.openwall.com/lists/oss-security/2012/09/02/4 http://www.openwall.com/lists/oss-security/2012/08/31/3 http://secunia.com/advisories/50468 http://git.videolan.org/?p=ffmpeg.git;a=commitdiff;h=2c22701c371c2f3dea21fcdbb97c981939fb77af http://ffmpeg.org/security.html https://ubuntu.com/security/notices/USN-1630-1 https://ubuntu.com/security/notices/USN-1705-1 Description: Unspecified vulnerability in the ac3_decode_frame function in libavcodec/ac3dec.c in FFmpeg before 0.11 and Libav 0.8.x before 0.8.4 has unknown impact and attack vectors, related to the "number of output channels" and "out of array writes." Ubuntu-Description: Notes: mdeslaur> ffmpeg-extra in multiverse needs to have matching version mdeslaur> libav-extra is built with tarball produced by libav package mdeslaur> cannot locate equivalent libav patch, even though 0.8.4 mdeslaur> is supposed to fix it. mdeslaur> libav 0.8.5 also says it fixes it, but still cannot locate mdeslaur> patch jdstrand> looking at the logic in the videolan patch and the code in ffmpeg, this may not affect the version of ffmpeg in Ubuntu 10.04 LTS Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: Patches_ffmpeg: upstream: http://git.videolan.org/?p=ffmpeg.git;a=commitdiff;h=2c22701c371c2f3dea21fcdbb97c981939fb77af upstream_ffmpeg: released (0.11) hardy_ffmpeg: ignored (reached end-of-life) lucid_ffmpeg: ignored natty_ffmpeg: DNE oneiric_ffmpeg: DNE precise_ffmpeg: DNE quantal_ffmpeg: DNE raring_ffmpeg: DNE saucy_ffmpeg: DNE devel_ffmpeg: DNE Patches_ffmpeg-extra: upstream_ffmpeg-extra: needs-triage hardy_ffmpeg-extra: DNE lucid_ffmpeg-extra: ignored natty_ffmpeg-extra: DNE oneiric_ffmpeg-extra: DNE precise_ffmpeg-extra: DNE quantal_ffmpeg-extra: DNE raring_ffmpeg-extra: DNE saucy_ffmpeg-extra: DNE devel_ffmpeg-extra: DNE Patches_libav: upstream_libav: needs-triage hardy_libav: DNE lucid_libav: DNE natty_libav: ignored (reached end-of-life) oneiric_libav: released (4:0.7.6-0ubuntu0.11.10.3) precise_libav: released (4:0.8.4-0ubuntu0.12.04.1) quantal_libav: released (6:0.8.4-0ubuntu0.12.10.1) raring_libav: released (6:0.8.4-0ubuntu0.12.10.1) saucy_libav: released (6:0.8.4-0ubuntu0.12.10.1) devel_libav: released (6:0.8.4-0ubuntu0.12.10.1) Patches_libav-extra: upstream_libav-extra: needs-triage hardy_libav-extra: DNE lucid_libav-extra: DNE natty_libav-extra: ignored (reached end-of-life) oneiric_libav-extra: released (4:0.7.6ubuntu0.11.10.3) precise_libav-extra: released (4:0.8.4ubuntu0.12.04.1) quantal_libav-extra: released (6:0.8.4ubuntu0.12.10.1) raring_libav-extra: released (6:0.8.4ubuntu0.12.10.1) saucy_libav-extra: released (6:0.8.4ubuntu0.12.10.1) devel_libav-extra: released (6:0.8.4ubuntu0.12.10.1)