vulnerability

SUSE: CVE-2018-13305: SUSE Linux Security Advisory

Severity
6
CVSS
(AV:N/AC:M/Au:N/C:P/I:N/A:P)
Published
Jul 5, 2018
Added
Jan 15, 2020
Modified
Feb 4, 2022

Description

In FFmpeg 4.0.1, due to a missing check for negative values of the mquant variable, the vc1_put_blocks_clamped function in libavcodec/vc1_block.c may trigger an out-of-array access while converting a crafted AVI file to MPEG4, leading to an information disclosure or a denial of service.

Solution(s)

suse-upgrade-ffmpegsuse-upgrade-ffmpeg-4-libavcodec-develsuse-upgrade-ffmpeg-4-libavdevice-develsuse-upgrade-ffmpeg-4-libavfilter-develsuse-upgrade-ffmpeg-4-libavformat-develsuse-upgrade-ffmpeg-4-libavresample-develsuse-upgrade-ffmpeg-4-libavutil-develsuse-upgrade-ffmpeg-4-libpostproc-develsuse-upgrade-ffmpeg-4-libswresample-develsuse-upgrade-ffmpeg-4-libswscale-develsuse-upgrade-ffmpeg-4-private-develsuse-upgrade-libavcodec-develsuse-upgrade-libavcodec57suse-upgrade-libavcodec58suse-upgrade-libavcodec58-32bitsuse-upgrade-libavcodec58-64bitsuse-upgrade-libavdevice57suse-upgrade-libavdevice58suse-upgrade-libavdevice58-32bitsuse-upgrade-libavdevice58-64bitsuse-upgrade-libavfilter6suse-upgrade-libavfilter7suse-upgrade-libavfilter7-32bitsuse-upgrade-libavfilter7-64bitsuse-upgrade-libavformat-develsuse-upgrade-libavformat57suse-upgrade-libavformat58suse-upgrade-libavformat58-32bitsuse-upgrade-libavformat58-64bitsuse-upgrade-libavresample-develsuse-upgrade-libavresample3suse-upgrade-libavresample4suse-upgrade-libavresample4-32bitsuse-upgrade-libavresample4-64bitsuse-upgrade-libavutil-develsuse-upgrade-libavutil55suse-upgrade-libavutil56suse-upgrade-libavutil56-32bitsuse-upgrade-libavutil56-64bitsuse-upgrade-libpostproc-develsuse-upgrade-libpostproc54suse-upgrade-libpostproc55suse-upgrade-libpostproc55-32bitsuse-upgrade-libpostproc55-64bitsuse-upgrade-libswresample-develsuse-upgrade-libswresample2suse-upgrade-libswresample3suse-upgrade-libswresample3-32bitsuse-upgrade-libswresample3-64bitsuse-upgrade-libswscale-develsuse-upgrade-libswscale4suse-upgrade-libswscale5suse-upgrade-libswscale5-32bitsuse-upgrade-libswscale5-64bit
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.