{"id":"SUSE-SU-2019:3184-2","summary":"Security update for ffmpeg","details":"This update for ffmpeg fixes the following issues:\n\nSecurity issues fixed:\t  \n- CVE-2019-17542: Fixed a heap-buffer overflow in vqa_decode_chunk due to an \n  out-of-array access (bsc#1154064).\n- CVE-2019-12730: Fixed an uninitialized use of variables due to an improper \n  check (bsc#1137526).\n- CVE-2019-9718: Fixed a denial of service in the subtitle decode (bsc#1129715).\n- CVE-2018-13301: Fixed a denial of service while converting a crafted AVI file \n  to MPEG4 (bsc#1100352).\n  ","modified":"2026-03-11T07:11:55.359612Z","published":"2020-07-07T11:43:16Z","related":["CVE-2018-13301","CVE-2019-12730","CVE-2019-17542","CVE-2019-9718"],"upstream":["CVE-2018-13301","CVE-2019-12730","CVE-2019-17542","CVE-2019-9718"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2019/suse-su-20193184-2/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1100352"},{"type":"REPORT","url":"https://bugzilla.suse.com/1129715"},{"type":"REPORT","url":"https://bugzilla.suse.com/1137526"},{"type":"REPORT","url":"https://bugzilla.suse.com/1154064"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-13301"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-12730"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-17542"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-9718"}],"affected":[{"package":{"name":"ffmpeg","ecosystem":"SUSE:Linux Enterprise Module for Package Hub 15 SP1","purl":"pkg:rpm/suse/ffmpeg&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP1"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.4.2-4.27.1"}]}],"ecosystem_specific":{"binaries":[{"libavdevice57":"3.4.2-4.27.1","libavfilter6":"3.4.2-4.27.1","ffmpeg":"3.4.2-4.27.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2019:3184-2.json"}}],"schema_version":"1.7.5"}