[Bug 1056760] New: VUL-0: CVE-2017-14056: In libavformat/rl2.c in FFmpeg 3.3.3, a DoS in rl2_read_header() due tolack of an EOF (End of File) check might cause huge CPU and memoryconsumption. When a crafted RL2 file, which claims a large"frame_count" field

http://bugzilla.opensuse.org/show_bug.cgi?id=1056760 Bug ID: 1056760 Summary: VUL-0: CVE-2017-14056: In libavformat/rl2.c in FFmpeg 3.3.3, a DoS in rl2_read_header() due tolack of an EOF (End of File) check might cause huge CPU and memoryconsumption. When a crafted RL2 file, which claims a large"frame_count" field Classification: openSUSE Product: openSUSE Distribution Version: Leap 42.3 Hardware: Other OS: Other Status: NEW Severity: Normal Priority: P5 - None Component: Security Assignee: jengelh@inai.de Reporter: abergmann@suse.com QA Contact: qa-bugs@suse.de CC: dimstar@opensuse.org, idonmez@suse.com Found By: Security Response Team Blocker: --- CVE-2017-14056 In libavformat/rl2.c in FFmpeg 3.3.3, a DoS in rl2_read_header() due to lack of an EOF (End of File) check might cause huge CPU and memory consumption. When a crafted RL2 file, which claims a large "frame_count" field in the header but does not contain sufficient backing data, is provided, the loops (for offset and size tables) would consume huge CPU and memory resources, since there is no EOF check inside these loops. Upstream fix: https://github.com/FFmpeg/FFmpeg/commit/96f24d1bee7fe7bac08e2b7c74db1a046c9d... References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2017-14056 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-14056 -- You are receiving this mail because: You are on the CC list for the bug.

http://bugzilla.opensuse.org/show_bug.cgi?id=1056760 http://bugzilla.opensuse.org/show_bug.cgi?id=1056760#c1 Alexander Bergmann <abergmann@suse.com> changed: What |Removed |Added ---------------------------------------------------------------------------- CC| |abergmann@suse.com --- Comment #1 from Alexander Bergmann <abergmann@suse.com> --- As we have currently no official ffmpeg maintainer in openSUSE I've added the last 3 persons that are visible inside the changes file. Feel free to submit a fix. -- You are receiving this mail because: You are on the CC list for the bug.

http://bugzilla.opensuse.org/show_bug.cgi?id=1056760 Alexander Bergmann <abergmann@suse.com> changed: What |Removed |Added ---------------------------------------------------------------------------- Summary|VUL-0: CVE-2017-14056: In |VUL-0: CVE-2017-14056: |libavformat/rl2.c in FFmpeg |ffmpeg: DoS in |3.3.3, a DoS in |rl2_read_header() due to |rl2_read_header() due |lack of an EOF (End of |tolack of an EOF (End of |File) check |File) check might cause | |huge CPU and | |memoryconsumption. When a | |crafted RL2 file, which | |claims a large"frame_count" | |field | -- You are receiving this mail because: You are on the CC list for the bug.

http://bugzilla.opensuse.org/show_bug.cgi?id=1056760 http://bugzilla.opensuse.org/show_bug.cgi?id=1056760#c2 Jan Engelhardt <jengelh@inai.de> changed: What |Removed |Added ---------------------------------------------------------------------------- Status|NEW |RESOLVED Resolution|--- |FIXED --- Comment #2 from Jan Engelhardt <jengelh@inai.de> --- Uhm of course we have maintainer. RL2 is not enabled in openSUSE. -- You are receiving this mail because: You are on the CC list for the bug.
participants (1)
-
bugzilla_noreply@novell.com