Bug 1205389 - (CVE-2022-3965) VUL-0: CVE-2022-3965: ffmpeg-4,ffmpeg: out of bounds read in smc_encode_stream()
(CVE-2022-3965)
VUL-0: CVE-2022-3965: ffmpeg-4,ffmpeg: out of bounds read in smc_encode_stream()
Status: NEW
Classification: openSUSE
Product: openSUSE Distribution
Classification: openSUSE
Component: Security
Leap 15.4
Other Other
: P3 - Medium : Normal (vote)
: ---
Assigned To: Jan Engelhardt
Security Team bot
https://smash.suse.de/issue/347881/
CVSSv3.1:SUSE:CVE-2022-3965:7.1:(AV:N...
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2022-11-14 09:36 UTC by Carlos López
Modified: 2022-11-14 11:00 UTC (History)
0 users

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Carlos López 2022-11-14 09:36:10 UTC
CVE-2022-3965

A vulnerability classified as problematic was found in ffmpeg. This vulnerability affects the function smc_encode_stream of the file libavcodec/smcenc.c of the component QuickTime Graphics Video Encoder. The manipulation of the argument y_size leads to out-of-bounds read. The attack can be initiated remotely. The name of the patch is 13c13109759090b7f7182480d075e13b36ed8edd. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-213544.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-3965
http://www.cvedetails.com/cve/CVE-2022-3965/
Comment 1 Carlos López 2022-11-14 09:36:32 UTC
This only affects openSUSE:Factory/ffmpeg-5
Comment 2 Jan Engelhardt 2022-11-14 11:00:19 UTC
smc is not enabled in openSUSE.