Bug 1189428 - (CVE-2021-38291) VUL-1: CVE-2021-38291: ffmpeg: FFmpeg version (git commit de8e6e67e7523e48bb27ac224a0b446df05e1640) suffers from a an assertion failure at src/libavutil/mathematics.c.
(CVE-2021-38291)
VUL-1: CVE-2021-38291: ffmpeg: FFmpeg version (git commit de8e6e67e7523e48bb2...
Status: NEW
Classification: Novell Products
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents
unspecified
Other Other
: P4 - Low : Minor
: ---
Assigned To: E-mail List
Security Team bot
https://smash.suse.de/issue/307150/
CVSSv3.1:SUSE:CVE-2021-38291:6.5:(AV:...
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2021-08-13 13:12 UTC by Marcus Meissner
Modified: 2021-09-29 11:51 UTC (History)
2 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Marcus Meissner 2021-08-13 13:12:55 UTC
CVE-2021-38291

FFmpeg version (git commit de8e6e67e7523e48bb27ac224a0b446df05e1640) suffers
from a an assertion failure at src/libavutil/mathematics.c.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2021-38291
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-38291
https://trac.ffmpeg.org/ticket/9312
Comment 1 Gabriele Sonnu 2021-09-29 11:51:04 UTC
Affected packages:

- SUSE:SLE-15:Update/ffmpeg               3.4.2
- SUSE:SLE-15-SP2:Update/ffmpeg           3.4.2
- openSUSE:Backports:SLE-15-SP2/ffmpeg-4  4.2.1
- openSUSE:Backports:SLE-15-SP3/ffmpeg-4    4.4
- openSUSE:Backports:SLE-15-SP4/ffmpeg-4    4.4
- openSUSE:Factory/ffmpeg-4                 4.4

Upstream fix for 3.4 branch [0] and 4.4/master [1].

[0] https://github.com/FFmpeg/FFmpeg/commit/a4a3fd814aac900175ec4a2811cb5bf98c1ddad3#diff-52921c91bf1031f341964f56d53a17ef1f5bd40eb33b92c2716a1c2e84905c75

[1] http://git.videolan.org/?p=ffmpeg.git;a=commitdiff;h=e01d306c647b5827102260b885faa223b646d2d1