Mageia 2024-0283: ffmpeg Security Advisory Updates
Summary
A vulnerability was found in FFmpeg up to 7.0.1. It has been classified
as critical. This affects the function pnm_decode_frame in the library
/libavcodec/pnmdec.c. The manipulation leads to heap-based buffer
overflow. It is possible to initiate the attack remotely. The exploit
has been disclosed to the public and may be used. (CVE-2024-7055)
A vulnerability, which was classified as critical, was found in FFmpeg
up to 5.1.5. This affects the function fill_audiodata of the file
/libswresample/swresample.c. The manipulation leads to heap-based buffer
overflow. It is possible to initiate the attack remotely.
(CVE-2024-7272)
References
- https://bugs.mageia.org/show_bug.cgi?id=33524
- https://lwn.net/Articles/985600/
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-7055
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-7272
Resolution
MGASA-2024-0283 - Updated ffmpeg packages fix security vulnerabilities
SRPMS
- 9/core/ffmpeg-5.1.6-1.mga9
- 9/tainted/ffmpeg-5.1.6-1.mga9.tainted