Rapid7 Vulnerability & Exploit Database

USN-2349-1: Libav vulnerabilities

Back to Search

USN-2349-1: Libav vulnerabilities

Severity
4
CVSS
(AV:L/AC:M/Au:N/C:P/I:P/A:P)
Published
09/17/2014
Created
07/25/2018
Added
09/19/2014
Modified
07/09/2020

Description

It was discovered that Libav incorrectly handled certain malformed mediafiles. If a user were tricked into opening a crafted media file, anattacker could cause a denial of service via application crash, or possiblyexecute arbitrary code with the privileges of the user invoking theprogram. The problem can be corrected by updating your system to the following package version: To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades. This update uses a new upstream release, which includes additional bugfixes. In general, a standard system update will make all the necessarychanges. LP: 1370175

Solution(s)

  • ubuntu-upgrade-libavcodec53
  • ubuntu-upgrade-libavformat53

With Rapid7 live dashboards, I have a clear view of all the assets on my network, which ones can be exploited, and what I need to do in order to reduce the risk in my environment in real-time. No other tool gives us that kind of value and insight.

– Scott Cheney, Manager of Information Security, Sierra View Medical Center

;