Bug 1205389 - (CVE-2022-3965) VUL-0: CVE-2022-3965: ffmpeg-4,ffmpeg: out of bounds read in smc_encode_stream()
VUL-0: CVE-2022-3965: ffmpeg-4,ffmpeg: out of bounds read in smc_encode_stream()
Status: NEW
Classification: openSUSE
Product: openSUSE Distribution
Classification: openSUSE
Component: Security
Leap 15.4
Other Other
: P3 - Medium : Normal (vote)
: ---
Assigned To: Jan Engelhardt
Security Team bot
Depends on:
  Show dependency treegraph
Reported: 2022-11-14 09:36 UTC by Carlos López
Modified: 2022-11-14 11:00 UTC (History)
0 users

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Note You need to log in before you can comment on or make changes to this bug.
Description Carlos López 2022-11-14 09:36:10 UTC

A vulnerability classified as problematic was found in ffmpeg. This vulnerability affects the function smc_encode_stream of the file libavcodec/smcenc.c of the component QuickTime Graphics Video Encoder. The manipulation of the argument y_size leads to out-of-bounds read. The attack can be initiated remotely. The name of the patch is 13c13109759090b7f7182480d075e13b36ed8edd. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-213544.

Comment 1 Carlos López 2022-11-14 09:36:32 UTC
This only affects openSUSE:Factory/ffmpeg-5
Comment 2 Jan Engelhardt 2022-11-14 11:00:19 UTC
smc is not enabled in openSUSE.