openSUSE Security Update : ffmpeg-4 (openSUSE-2019-691)

high Nessus Plugin ID 123300

Language:

Synopsis

The remote openSUSE host is missing a security update.

Description

This update for ffmpeg-4 to version 4.0.2 fixes the following issues :

These security issues were fixed :

- CVE-2018-15822: The flv_write_packet function did not check for an empty audio packet, leading to an assertion failure and DoS (bsc#1105869).

- CVE-2018-13300: An improper argument passed to the avpriv_request_sample function may have triggered an out-of-array read while converting a crafted AVI file to MPEG4, leading to a denial of service and possibly an information disclosure (bsc#1100348).

These non-security issues were fixed :

- Enable webvtt encoders and decoders (boo#1092241).

- Build codec2 encoder and decoder, add libcodec2 to enable_decoders and enable_encoders.

- Enable mpeg 1 and 2 encoders.

Solution

Update the affected ffmpeg-4 packages.

See Also

https://bugzilla.opensuse.org/show_bug.cgi?id=1092241

https://bugzilla.opensuse.org/show_bug.cgi?id=1100348

https://bugzilla.opensuse.org/show_bug.cgi?id=1105869

Plugin Details

Severity: High

ID: 123300

File Name: openSUSE-2019-691.nasl

Version: 1.6

Type: local

Agent: unix

Published: 3/27/2019

Updated: 6/11/2024

Supported Sensors: Frictionless Assessment AWS, Frictionless Assessment Azure, Frictionless Assessment Agent, Nessus Agent, Continuous Assessment, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 5.2

CVSS v2

Risk Factor: Medium

Base Score: 5.8

Temporal Score: 4.3

Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:N/A:P

CVSS Score Source: CVE-2018-13300

CVSS v3

Risk Factor: High

Base Score: 8.1

Temporal Score: 7.1

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: cpe:/o:novell:opensuse:15.0, p-cpe:/a:novell:opensuse:ffmpeg-4-libswresample-devel, p-cpe:/a:novell:opensuse:libpostproc55, p-cpe:/a:novell:opensuse:ffmpeg-4-libavfilter-devel, p-cpe:/a:novell:opensuse:libavfilter7-debuginfo, p-cpe:/a:novell:opensuse:libswscale5, p-cpe:/a:novell:opensuse:libavresample4-debuginfo, p-cpe:/a:novell:opensuse:ffmpeg-4-libavresample-devel, p-cpe:/a:novell:opensuse:ffmpeg-4-libavutil-devel, p-cpe:/a:novell:opensuse:libavcodec58-debuginfo, p-cpe:/a:novell:opensuse:libavresample4, p-cpe:/a:novell:opensuse:ffmpeg-4-private-devel, p-cpe:/a:novell:opensuse:ffmpeg-4-libavdevice-devel, p-cpe:/a:novell:opensuse:libavutil56, p-cpe:/a:novell:opensuse:libavformat58, p-cpe:/a:novell:opensuse:libpostproc55-debuginfo, p-cpe:/a:novell:opensuse:libavfilter7, p-cpe:/a:novell:opensuse:libavcodec58, p-cpe:/a:novell:opensuse:libavutil56-debuginfo, p-cpe:/a:novell:opensuse:libavformat58-debuginfo, p-cpe:/a:novell:opensuse:ffmpeg-4-libavformat-devel, p-cpe:/a:novell:opensuse:libavdevice58-debuginfo, p-cpe:/a:novell:opensuse:libswresample3, p-cpe:/a:novell:opensuse:ffmpeg-4-debugsource, p-cpe:/a:novell:opensuse:libswscale5-debuginfo, p-cpe:/a:novell:opensuse:ffmpeg-4-libswscale-devel, p-cpe:/a:novell:opensuse:libswresample3-debuginfo, p-cpe:/a:novell:opensuse:libavdevice58, p-cpe:/a:novell:opensuse:ffmpeg-4-libavcodec-devel, p-cpe:/a:novell:opensuse:ffmpeg-4-libpostproc-devel

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/SuSE/release, Host/SuSE/rpm-list

Exploit Ease: No known exploits are available

Patch Publication Date: 3/23/2019

Vulnerability Publication Date: 7/5/2018

Reference Information

CVE: CVE-2018-13300, CVE-2018-15822