Bug 1223255 (CVE-2023-50009)

Summary: VUL-0: CVE-2023-50009: ffmpeg,ffmpeg-4: arbitrary code execution via the ff_gaussian_blur_8 function in libavfilter/edge_template.c
Product: [Novell Products] SUSE Security Incidents Reporter: SMASH SMASH <smash_bz>
Component: IncidentsAssignee: Security Team bot <security-team>
Status: RESOLVED FIXED QA Contact: Security Team bot <security-team>
Severity: Normal    
Priority: P3 - Medium CC: abergmann, camila.matos, qzhao
Version: unspecified   
Target Milestone: ---   
Hardware: Other   
OS: Other   
URL: https://smash.suse.de/issue/402762/
Whiteboard: CVSSv3.1:SUSE:CVE-2023-50009:8.8:(AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Found By: Security Response Team Services Priority:
Business Priority: Blocker: ---
Marketing QA Status: --- IT Deployment: ---

Description SMASH SMASH 2024-04-22 12:32:39 UTC
Buffer Overflow vulnerability in Ffmpeg v.n6.1-3-g466799d4f5 allows a local attacker to execute arbitrary code via the ff_gaussian_blur_8 function in libavfilter/edge_template.c:116:5 component.

References:
https://github.com/FFmpeg/FFmpeg
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-50009
https://www.cve.org/CVERecord?id=CVE-2023-50009
https://ffmpeg.org/
https://trac.ffmpeg.org/ticket/10699
https://bugzilla.redhat.com/show_bug.cgi?id=2276128
Comment 3 Camila Camargo de Matos 2024-05-17 16:59:59 UTC
The only package affected by this issue was openSUSE:Factory/ffmpeg-5. The fix has already landed in this package and, therefore, this bug will be closed as RESOLVED/FIXED.