Bugzilla – Bug 1101889
VUL-1: CVE-2018-14395: ffmpeg: libavformat/movenc.c allows attackers to cause a denial of service (application crash caused by a divide-by-zero error)
Last modified: 2019-10-15 06:53:34 UTC
CVE-2018-14395 libavformat/movenc.c in FFmpeg before 4.0.2 allows attackers to cause a denial of service (application crash caused by a divide-by-zero error) with a user crafted audio file when converting to the MOV audio format. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2018-14395 https://github.com/FFmpeg/FFmpeg/commit/fa19fbcf712a6a6cc5a5cfdc3254a97b9bce6582
Hi Yifan, can you have your team take this. Thanks.
The fix has already been in multimedia:libs/ffmpeg-4.
fixed
sle15 unfixed
SUSE-SU-2019:1299-1: An update that fixes two vulnerabilities is now available. Category: security (low) Bug References: 1101888,1101889 CVE References: CVE-2018-14394,CVE-2018-14395 Sources used: SUSE Linux Enterprise Workstation Extension 15 (src): ffmpeg-3.4.2-4.17.26 SUSE Linux Enterprise Module for Packagehub Subpackages 15 (src): ffmpeg-3.4.2-4.17.26 SUSE Linux Enterprise Module for Open Buildservice Development Tools 15 (src): ffmpeg-3.4.2-4.17.26 SUSE Linux Enterprise Module for Desktop Applications 15 (src): ffmpeg-3.4.2-4.17.26 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
SUSE-SU-2019:1299-2: An update that fixes two vulnerabilities is now available. Category: security (low) Bug References: 1101888,1101889 CVE References: CVE-2018-14394,CVE-2018-14395 Sources used: SUSE Linux Enterprise Workstation Extension 15-SP1 (src): ffmpeg-3.4.2-4.17.26 SUSE Linux Enterprise Module for Open Buildservice Development Tools 15-SP1 (src): ffmpeg-3.4.2-4.17.26 SUSE Linux Enterprise Module for Desktop Applications 15-SP1 (src): ffmpeg-3.4.2-4.17.26 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.