- -------------------------------------------------------------------------
Debian LTS Advisory DLA-4039-1                debian-lts@lists.debian.org
https://www.debian.org/lts/security/                    Thorsten Alteholz
February 01, 2025                             https://wiki.debian.org/LTS
- -------------------------------------------------------------------------

Package        : ffmpeg
Version        : 7:4.3.8-0+deb11u2
CVE ID         : CVE-2024-35367 CVE-2024-35368 CVE-2024-36618


Several issues have been found in ffmpeg, a package that contains tools
for transcoding, streaming and playing of multimedia files
Those issues are related to possible integer overflows, double-free on
errors and out-of-bounds access.


For Debian 11 bullseye, these problems have been fixed in version
7:4.3.8-0+deb11u2.

We recommend that you upgrade your ffmpeg packages.

For the detailed security status of ffmpeg please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/ffmpeg

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS

(I had to resend this email, so sorry if you are getting this twice)

Debian LTS: DLA-4039-1: ffmpeg Security Advisory Updates

February 1, 2025
Several issues have been found in ffmpeg, a package that contains tools for transcoding, streaming and playing of multimedia files Those issues are related to possible integer over...

Summary

Several issues have been found in ffmpeg, a package that contains tools
for transcoding, streaming and playing of multimedia files
Those issues are related to possible integer overflows, double-free on
errors and out-of-bounds access.


For Debian 11 bullseye, these problems have been fixed in version
7:4.3.8-0+deb11u2.

We recommend that you upgrade your ffmpeg packages.

For the detailed security status of ffmpeg please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/ffmpeg

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS

(I had to resend this email, so sorry if you are getting this twice)


Severity
Package : ffmpeg
Version : 7:4.3.8-0+deb11u2
CVE ID : CVE-2024-35367 CVE-2024-35368 CVE-2024-36618

Related News