Candidate: CVE-2014-9676 PublicDate: 2015-02-28 01:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-9676 http://seclists.org/oss-sec/2015/q1/38 Description: The seg_write_packet function in libavformat/segment.c in ffmpeg 2.1.4 and earlier does not free the correct memory location, which allows remote attackers to cause a denial of service ("invalid memory handler") and possibly execute arbitrary code via a crafted video that triggers a use after free. Ubuntu-Description: It was discovered that Libav incorrectly handled certain media files. An attacker could possibly use this issue to cause a denial of service or other unspecified impact. Notes: tyhicks> from what I can tell, libav 9.0 to 11.1 is affected with upstream git commit eb447d515956b3ce182d9750083131735f00324c introducing the issue Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: Patches_ffmpeg: upstream: https://github.com/FFmpeg/FFmpeg/commit/b3f04657368a32a9903406395f865e230b1de348 upstream_ffmpeg: needs-triage lucid_ffmpeg: ignored (reached end-of-life) precise_ffmpeg: DNE precise/esm_ffmpeg: DNE trusty_ffmpeg: DNE trusty/esm_ffmpeg: DNE utopic_ffmpeg: DNE vivid_ffmpeg: not-affected (7:2.5.4-1) vivid/stable-phone-overlay_ffmpeg: DNE vivid/ubuntu-core_ffmpeg: DNE wily_ffmpeg: not-affected (7:2.5.4-1) xenial_ffmpeg: not-affected (7:2.5.4-1) yakkety_ffmpeg: not-affected (7:2.5.4-1) zesty_ffmpeg: not-affected (7:2.5.4-1) artful_ffmpeg: not-affected (7:2.5.4-1) bionic_ffmpeg: not-affected (7:2.5.4-1) cosmic_ffmpeg: not-affected (7:2.5.4-1) disco_ffmpeg: not-affected (7:2.5.4-1) devel_ffmpeg: not-affected (7:2.5.4-1) Patches_libav: upstream: https://git.libav.org/?p=libav.git;a=commitdiff;h=b3f04657368a32a9903406395f865e230b1de348 upstream_libav: needs-triage lucid_libav: DNE precise_libav: not-affected (4:0.8.16-0ubuntu0.12.04.1) precise/esm_libav: DNE (precise was not-affected [4:0.8.16-0ubuntu0.12.04.1]) trusty_libav: ignored (reached end-of-life) trusty/esm_libav: DNE (trusty was needed) utopic_libav: ignored (reached end-of-life) vivid_libav: not-affected (6:11.2-1) vivid/stable-phone-overlay_libav: DNE vivid/ubuntu-core_libav: DNE wily_libav: DNE xenial_libav: DNE yakkety_libav: DNE zesty_libav: DNE artful_libav: DNE bionic_libav: DNE cosmic_libav: DNE disco_libav: DNE devel_libav: DNE