본문 바로가기

취약점 정보2

ffmpeg security update

728x90
Several vulnerabilities have been discovered in FFmpeg, a multimedia
player, server and encoder. These issues could lead to Denial-of-Service
and, in some situation, the execution of arbitrary code.

CVE-2017-9608

    Yihan Lian of Qihoo 360 GearTeam discovered a NULL pointer access when
    parsing a crafted MOV file.

CVE-2017-9993

    Thierry Foucu discovered that it was possible to leak information from
    files and symlinks ending in common multimedia extensions, using the
    HTTP Live Streaming.

CVE-2017-11399

    Liu Bingchang of IIE discovered an integer overflow in the APE decoder
    that can be triggered by a crafted APE file.

CVE-2017-11665

    JunDong Xie of Ant-financial Light-Year Security Lab discovered that
    an attacker able to craft a RTMP stream can crash FFmpeg.

CVE-2017-11719

    Liu Bingchang of IIE discovered an out-of-bound access that can be
    triggered by a crafted DNxHD file. 

For the stable distribution (stretch), these problems have been fixed in
version 7:3.2.7-1~deb9u1.

We recommend that you upgrade your ffmpeg packages.
728x90

'취약점 정보2' 카테고리의 다른 글

libgd2 security update  (0) 2017.09.05
어도비 제품군 업데이트 안내  (0) 2017.09.01
WinDbg 업데이트  (0) 2017.08.30
Lg 모바일 8월 업데이트 안내  (0) 2017.08.25
삼성 모바일 8월 업데이트 안내  (0) 2017.08.25