[Bug 1100359] New: VUL-1: CVE-2018-13304: ffmpeg: Improper maintenance of the consistency between the context profile field and studio_profile in libavcodec may trigger anassertion failure
http://bugzilla.opensuse.org/show_bug.cgi?id=1100359 Bug ID: 1100359 Summary: VUL-1: CVE-2018-13304: ffmpeg: Improper maintenance of the consistency between the context profile field and studio_profile in libavcodec may trigger anassertion failure Classification: openSUSE Product: openSUSE Distribution Version: Leap 42.3 Hardware: Other URL: https://smash.suse.de/issue/209619/ OS: Other Status: NEW Severity: Minor Priority: P5 - None Component: Security Assignee: jengelh@inai.de Reporter: jsegitz@suse.com QA Contact: security-team@suse.de Found By: Security Response Team Blocker: --- CVE-2018-13304 In libavcodec in FFmpeg 4.0.1, improper maintenance of the consistency between the context profile field and studio_profile in libavcodec may trigger an assertion failure while converting a crafted AVI file to MPEG4, leading to a denial of service, related to error_resilience.c, h263dec.c, and mpeg4videodec.c. No maintainer, would you please take this one? References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2018-13304 https://github.com/FFmpeg/FFmpeg/commit/bd27a9364ca274ca97f1df6d984e88a0700f... -- You are receiving this mail because: You are on the CC list for the bug.
participants (1)
-
bugzilla_noreply@novell.com