Candidate: CVE-2014-8549 PublicDate: 2014-11-05 11:55:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8549 http://www.ffmpeg.org/security.html Description: libavcodec/on2avc.c in FFmpeg before 2.4.2 does not constrain the number of channels to at most 2, which allows remote attackers to cause a denial of service (out-of-bounds access) or possibly have unspecified other impact via crafted On2 data. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: Patches_ffmpeg: upstream: http://git.videolan.org/?p=ffmpeg.git;a=commit;h=550f3e9df3410b3dd975e590042c0d83e20a8da3 upstream_ffmpeg: needs-triage lucid_ffmpeg: ignored (reached end-of-life) precise_ffmpeg: DNE trusty_ffmpeg: DNE trusty/esm_ffmpeg: DNE utopic_ffmpeg: DNE vivid_ffmpeg: not-affected (7:2.5.4-1) devel_ffmpeg: not-affected (7:2.5.4-1) Patches_libav: upstream: https://git.libav.org/?p=libav.git;a=commit;h=cee4490b521fd0d02476d46aa2598af24fb8d686 upstream_libav: released (11.2) lucid_libav: DNE precise_libav: not-affected (code not present) trusty_libav: not-affected (code not present) trusty/esm_libav: DNE (trusty was not-affected [code not present]) utopic_libav: ignored (reached end-of-life) vivid_libav: not-affected (6:11.2-1) devel_libav: not-affected (6:11.2-1)