Bug 1189428 (CVE-2021-38291)

Summary: VUL-1: CVE-2021-38291: ffmpeg: FFmpeg version (git commit de8e6e67e7523e48bb27ac224a0b446df05e1640) suffers from a an assertion failure at src/libavutil/mathematics.c.
Product: [Novell Products] SUSE Security Incidents Reporter: Marcus Meissner <meissner>
Component: IncidentsAssignee: E-mail List <gnome-bugs>
Status: NEW --- QA Contact: Security Team bot <security-team>
Severity: Minor    
Priority: P4 - Low CC: gabriele.sonnu, smash_bz
Version: unspecified   
Target Milestone: ---   
Hardware: Other   
OS: Other   
URL: https://smash.suse.de/issue/307150/
Whiteboard: CVSSv3.1:SUSE:CVE-2021-38291:6.5:(AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
Found By: Security Response Team Services Priority:
Business Priority: Blocker: ---
Marketing QA Status: --- IT Deployment: ---

Description Marcus Meissner 2021-08-13 13:12:55 UTC
CVE-2021-38291

FFmpeg version (git commit de8e6e67e7523e48bb27ac224a0b446df05e1640) suffers
from a an assertion failure at src/libavutil/mathematics.c.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2021-38291
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-38291
https://trac.ffmpeg.org/ticket/9312
Comment 1 Gabriele Sonnu 2021-09-29 11:51:04 UTC
Affected packages:

- SUSE:SLE-15:Update/ffmpeg               3.4.2
- SUSE:SLE-15-SP2:Update/ffmpeg           3.4.2
- openSUSE:Backports:SLE-15-SP2/ffmpeg-4  4.2.1
- openSUSE:Backports:SLE-15-SP3/ffmpeg-4    4.4
- openSUSE:Backports:SLE-15-SP4/ffmpeg-4    4.4
- openSUSE:Factory/ffmpeg-4                 4.4

Upstream fix for 3.4 branch [0] and 4.4/master [1].

[0] https://github.com/FFmpeg/FFmpeg/commit/a4a3fd814aac900175ec4a2811cb5bf98c1ddad3#diff-52921c91bf1031f341964f56d53a17ef1f5bd40eb33b92c2716a1c2e84905c75

[1] http://git.videolan.org/?p=ffmpeg.git;a=commitdiff;h=e01d306c647b5827102260b885faa223b646d2d1