{"id":"UBUNTU-CVE-2018-13302","details":"In FFmpeg 4.0.1, improper handling of frame types (other than EAC3_FRAME_TYPE_INDEPENDENT) that have multiple independent substreams in the handle_eac3 function in libavformat/movenc.c may trigger an out-of-array access while converting a crafted AVI file to MPEG4, leading to a denial of service or possibly unspecified other impact.","modified":"2026-01-20T16:43:51.152995Z","published":"2018-07-05T17:29:00Z","upstream":["CVE-2018-13302"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2018-13302"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2018-13302"}],"affected":[{"package":{"name":"ffmpeg","ecosystem":"Ubuntu:16.04:LTS","purl":"pkg:deb/ubuntu/ffmpeg@7:2.8.15-0ubuntu0.16.04.1?arch=source&distro=xenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"7:2.8.15-0ubuntu0.16.04.1"}]}],"versions":["7:2.7.2-1build1","7:2.8.1-1ubuntu1","7:2.8.2-1ubuntu1","7:2.8.3-1","7:2.8.4-1","7:2.8.4-1ubuntu1","7:2.8.4-1ubuntu2","7:2.8.4-1ubuntu3","7:2.8.4-1ubuntu4","7:2.8.6-1ubuntu1","7:2.8.6-1ubuntu2","7:2.8.8-0ubuntu0.16.04.1","7:2.8.10-0ubuntu0.16.04.1","7:2.8.11-0ubuntu0.16.04.1","7:2.8.14-0ubuntu0.16.04.1"],"ecosystem_specific":{"binaries":[{"binary_name":"ffmpeg","binary_version":"7:2.8.15-0ubuntu0.16.04.1"},{"binary_name":"libav-tools","binary_version":"7:2.8.15-0ubuntu0.16.04.1"},{"binary_name":"libavcodec-dev","binary_version":"7:2.8.15-0ubuntu0.16.04.1"},{"binary_name":"libavcodec-extra","binary_version":"7:2.8.15-0ubuntu0.16.04.1"},{"binary_name":"libavcodec-ffmpeg-extra56","binary_version":"7:2.8.15-0ubuntu0.16.04.1"},{"binary_name":"libavcodec-ffmpeg56","binary_version":"7:2.8.15-0ubuntu0.16.04.1"},{"binary_name":"libavdevice-dev","binary_version":"7:2.8.15-0ubuntu0.16.04.1"},{"binary_name":"libavdevice-ffmpeg56","binary_version":"7:2.8.15-0ubuntu0.16.04.1"},{"binary_name":"libavfilter-dev","binary_version":"7:2.8.15-0ubuntu0.16.04.1"},{"binary_name":"libavfilter-ffmpeg5","binary_version":"7:2.8.15-0ubuntu0.16.04.1"},{"binary_name":"libavformat-dev","binary_version":"7:2.8.15-0ubuntu0.16.04.1"},{"binary_name":"libavformat-ffmpeg56","binary_version":"7:2.8.15-0ubuntu0.16.04.1"},{"binary_name":"libavresample-dev","binary_version":"7:2.8.15-0ubuntu0.16.04.1"},{"binary_name":"libavresample-ffmpeg2","binary_version":"7:2.8.15-0ubuntu0.16.04.1"},{"binary_name":"libavutil-dev","binary_version":"7:2.8.15-0ubuntu0.16.04.1"},{"binary_name":"libavutil-ffmpeg54","binary_version":"7:2.8.15-0ubuntu0.16.04.1"},{"binary_name":"libpostproc-dev","binary_version":"7:2.8.15-0ubuntu0.16.04.1"},{"binary_name":"libpostproc-ffmpeg53","binary_version":"7:2.8.15-0ubuntu0.16.04.1"},{"binary_name":"libswresample-dev","binary_version":"7:2.8.15-0ubuntu0.16.04.1"},{"binary_name":"libswresample-ffmpeg1","binary_version":"7:2.8.15-0ubuntu0.16.04.1"},{"binary_name":"libswscale-dev","binary_version":"7:2.8.15-0ubuntu0.16.04.1"},{"binary_name":"libswscale-ffmpeg3","binary_version":"7:2.8.15-0ubuntu0.16.04.1"}],"availability":"No subscription required"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2018/UBUNTU-CVE-2018-13302.json"}},{"package":{"name":"oxide-qt","ecosystem":"Ubuntu:16.04:LTS","purl":"pkg:deb/ubuntu/oxide-qt@1.21.5-0ubuntu0.16.04.1?arch=source&distro=xenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.9.5-0ubuntu1","1.10.3-0ubuntu0.15.10.1","1.10.3-0ubuntu0.15.10.2","1.11.3-0ubuntu3","1.11.4-0ubuntu1","1.11.5-0ubuntu1","1.12.5-0ubuntu1","1.12.6-0ubuntu1","1.12.7-0ubuntu1","1.13.6-0ubuntu1","1.14.7-0ubuntu1","1.14.9-0ubuntu0.16.04.1","1.15.7-0ubuntu0.16.04.1","1.15.8-0ubuntu0.16.04.1","1.16.5-0ubuntu0.16.04.1","1.17.7-0ubuntu0.16.04.1","1.17.9-0ubuntu0.16.04.1","1.18.3-0ubuntu0.16.04.1","1.18.5-0ubuntu0.16.04.1","1.19.4-0ubuntu0.16.04.1","1.20.4-0ubuntu0.16.04.1","1.21.5-0ubuntu0.16.04.1"],"ecosystem_specific":{"binaries":[{"binary_name":"liboxideqt-qmlplugin","binary_version":"1.21.5-0ubuntu0.16.04.1"},{"binary_name":"liboxideqtcore-dev","binary_version":"1.21.5-0ubuntu0.16.04.1"},{"binary_name":"liboxideqtcore0","binary_version":"1.21.5-0ubuntu0.16.04.1"},{"binary_name":"liboxideqtquick-dev","binary_version":"1.21.5-0ubuntu0.16.04.1"},{"binary_name":"liboxideqtquick0","binary_version":"1.21.5-0ubuntu0.16.04.1"},{"binary_name":"oxideqt-codecs","binary_version":"1.21.5-0ubuntu0.16.04.1"},{"binary_name":"oxideqt-codecs-extra","binary_version":"1.21.5-0ubuntu0.16.04.1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2018/UBUNTU-CVE-2018-13302.json"}},{"package":{"name":"gst-libav1.0","ecosystem":"Ubuntu:16.04:LTS","purl":"pkg:deb/ubuntu/gst-libav1.0@1.8.3-1ubuntu0.2?arch=source&distro=xenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.6.0-1","1.6.0-2","1.6.1-1","1.6.2-1","1.7.1-1","1.7.2-1","1.7.90-1","1.8.0-1","1.8.1-1~ubuntu1","1.8.2-1~ubuntu1","1.8.3-1ubuntu0.1","1.8.3-1ubuntu0.2"],"ecosystem_specific":{"binaries":[{"binary_name":"gstreamer1.0-libav","binary_version":"1.8.3-1ubuntu0.2"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2018/UBUNTU-CVE-2018-13302.json"}},{"package":{"name":"kino","ecosystem":"Ubuntu:16.04:LTS","purl":"pkg:deb/ubuntu/kino@1.3.4-2.1build2?arch=source&distro=xenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.3.4-2.1build2"],"ecosystem_specific":{"binaries":[{"binary_name":"kino","binary_version":"1.3.4-2.1build2"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2018/UBUNTU-CVE-2018-13302.json"}},{"package":{"name":"mythtv","ecosystem":"Ubuntu:16.04:LTS","purl":"pkg:deb/ubuntu/mythtv@2:0.28.0+fixes.20160413.15cf421-0ubuntu2.16.04.1?arch=source&distro=xenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2:0.27.1+fixes.20140624.aa822f5-0ubuntu6","2:0.27.1+fixes.20140624.aa822f5-0ubuntu7","2:0.27.1+fixes.20140624.aa822f5-0ubuntu9","2:0.28.0+fixes.20160217.44fd8a6-0ubuntu4","2:0.28.0+fixes.20160229.ae35a28-0ubuntu1","2:0.28.0+fixes.20160321.39e409d-0ubuntu1","2:0.28.0+fixes.20160321.39e409d-0ubuntu2","2:0.28.0+fixes.20160325.2520617-0ubuntu3","2:0.28.0+fixes.20160413.15cf421-0ubuntu1","2:0.28.0+fixes.20160413.15cf421-0ubuntu2","2:0.28.0+fixes.20160413.15cf421-0ubuntu2.16.04.1"],"ecosystem_specific":{"binaries":[{"binary_name":"libmyth-0.28-0","binary_version":"2:0.28.0+fixes.20160413.15cf421-0ubuntu2.16.04.1"},{"binary_name":"libmyth-dev","binary_version":"2:0.28.0+fixes.20160413.15cf421-0ubuntu2.16.04.1"},{"binary_name":"libmyth-python","binary_version":"2:0.28.0+fixes.20160413.15cf421-0ubuntu2.16.04.1"},{"binary_name":"libmythtv-perl","binary_version":"2:0.28.0+fixes.20160413.15cf421-0ubuntu2.16.04.1"},{"binary_name":"mytharchive","binary_version":"2:0.28.0+fixes.20160413.15cf421-0ubuntu2.16.04.1"},{"binary_name":"mythbrowser","binary_version":"2:0.28.0+fixes.20160413.15cf421-0ubuntu2.16.04.1"},{"binary_name":"mythgallery","binary_version":"2:0.28.0+fixes.20160413.15cf421-0ubuntu2.16.04.1"},{"binary_name":"mythgame","binary_version":"2:0.28.0+fixes.20160413.15cf421-0ubuntu2.16.04.1"},{"binary_name":"mythmusic","binary_version":"2:0.28.0+fixes.20160413.15cf421-0ubuntu2.16.04.1"},{"binary_name":"mythnetvision","binary_version":"2:0.28.0+fixes.20160413.15cf421-0ubuntu2.16.04.1"},{"binary_name":"mythnews","binary_version":"2:0.28.0+fixes.20160413.15cf421-0ubuntu2.16.04.1"},{"binary_name":"mythplugins","binary_version":"2:0.28.0+fixes.20160413.15cf421-0ubuntu2.16.04.1"},{"binary_name":"mythtv","binary_version":"2:0.28.0+fixes.20160413.15cf421-0ubuntu2.16.04.1"},{"binary_name":"mythtv-backend","binary_version":"2:0.28.0+fixes.20160413.15cf421-0ubuntu2.16.04.1"},{"binary_name":"mythtv-backend-master","binary_version":"2:0.28.0+fixes.20160413.15cf421-0ubuntu2.16.04.1"},{"binary_name":"mythtv-common","binary_version":"2:0.28.0+fixes.20160413.15cf421-0ubuntu2.16.04.1"},{"binary_name":"mythtv-database","binary_version":"2:0.28.0+fixes.20160413.15cf421-0ubuntu2.16.04.1"},{"binary_name":"mythtv-frontend","binary_version":"2:0.28.0+fixes.20160413.15cf421-0ubuntu2.16.04.1"},{"binary_name":"mythtv-theme-mythbuntu","binary_version":"2:0.28.0+fixes.20160413.15cf421-0ubuntu2.16.04.1"},{"binary_name":"mythtv-transcode-utils","binary_version":"2:0.28.0+fixes.20160413.15cf421-0ubuntu2.16.04.1"},{"binary_name":"mythweather","binary_version":"2:0.28.0+fixes.20160413.15cf421-0ubuntu2.16.04.1"},{"binary_name":"mythweb","binary_version":"2:0.28.0+fixes.20160413.15cf421-0ubuntu2.16.04.1"},{"binary_name":"mythzoneminder","binary_version":"2:0.28.0+fixes.20160413.15cf421-0ubuntu2.16.04.1"},{"binary_name":"php-mythtv","binary_version":"2:0.28.0+fixes.20160413.15cf421-0ubuntu2.16.04.1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2018/UBUNTU-CVE-2018-13302.json"}},{"package":{"name":"ffmpeg","ecosystem":"Ubuntu:18.04:LTS","purl":"pkg:deb/ubuntu/ffmpeg@7:3.4.4-0ubuntu0.18.04.1?arch=source&distro=bionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"7:3.4.4-0ubuntu0.18.04.1"}]}],"versions":["7:3.3.4-2","7:3.3.4-2build3","7:3.4-2ubuntu2","7:3.4-4","7:3.4-4build1","7:3.4.1-1","7:3.4.1-1build1","7:3.4.2-1","7:3.4.2-1build1","7:3.4.2-2"],"ecosystem_specific":{"binaries":[{"binary_name":"ffmpeg","binary_version":"7:3.4.4-0ubuntu0.18.04.1"},{"binary_name":"libavcodec-dev","binary_version":"7:3.4.4-0ubuntu0.18.04.1"},{"binary_name":"libavcodec-extra","binary_version":"7:3.4.4-0ubuntu0.18.04.1"},{"binary_name":"libavcodec-extra57","binary_version":"7:3.4.4-0ubuntu0.18.04.1"},{"binary_name":"libavcodec57","binary_version":"7:3.4.4-0ubuntu0.18.04.1"},{"binary_name":"libavdevice-dev","binary_version":"7:3.4.4-0ubuntu0.18.04.1"},{"binary_name":"libavdevice57","binary_version":"7:3.4.4-0ubuntu0.18.04.1"},{"binary_name":"libavfilter-dev","binary_version":"7:3.4.4-0ubuntu0.18.04.1"},{"binary_name":"libavfilter-extra","binary_version":"7:3.4.4-0ubuntu0.18.04.1"},{"binary_name":"libavfilter-extra6","binary_version":"7:3.4.4-0ubuntu0.18.04.1"},{"binary_name":"libavfilter6","binary_version":"7:3.4.4-0ubuntu0.18.04.1"},{"binary_name":"libavformat-dev","binary_version":"7:3.4.4-0ubuntu0.18.04.1"},{"binary_name":"libavformat57","binary_version":"7:3.4.4-0ubuntu0.18.04.1"},{"binary_name":"libavresample-dev","binary_version":"7:3.4.4-0ubuntu0.18.04.1"},{"binary_name":"libavresample3","binary_version":"7:3.4.4-0ubuntu0.18.04.1"},{"binary_name":"libavutil-dev","binary_version":"7:3.4.4-0ubuntu0.18.04.1"},{"binary_name":"libavutil55","binary_version":"7:3.4.4-0ubuntu0.18.04.1"},{"binary_name":"libpostproc-dev","binary_version":"7:3.4.4-0ubuntu0.18.04.1"},{"binary_name":"libpostproc54","binary_version":"7:3.4.4-0ubuntu0.18.04.1"},{"binary_name":"libswresample-dev","binary_version":"7:3.4.4-0ubuntu0.18.04.1"},{"binary_name":"libswresample2","binary_version":"7:3.4.4-0ubuntu0.18.04.1"},{"binary_name":"libswscale-dev","binary_version":"7:3.4.4-0ubuntu0.18.04.1"},{"binary_name":"libswscale4","binary_version":"7:3.4.4-0ubuntu0.18.04.1"}],"availability":"No subscription required"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2018/UBUNTU-CVE-2018-13302.json"}},{"package":{"name":"gst-libav1.0","ecosystem":"Ubuntu:18.04:LTS","purl":"pkg:deb/ubuntu/gst-libav1.0@1.14.5-0ubuntu1~18.04.1?arch=source&distro=bionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.12.2-1","1.12.3-1","1.12.4-1","1.13.91-1","1.14.0-1","1.14.1-1~ubuntu18.04.1","1.14.4-0ubuntu1~ubuntu18.04.1","1.14.5-0ubuntu1~18.04.1"],"ecosystem_specific":{"binaries":[{"binary_name":"gstreamer1.0-libav","binary_version":"1.14.5-0ubuntu1~18.04.1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2018/UBUNTU-CVE-2018-13302.json"}},{"package":{"name":"kino","ecosystem":"Ubuntu:18.04:LTS","purl":"pkg:deb/ubuntu/kino@1.3.4-2.4?arch=source&distro=bionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.3.4-2.3","1.3.4-2.4"],"ecosystem_specific":{"binaries":[{"binary_name":"kino","binary_version":"1.3.4-2.4"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2018/UBUNTU-CVE-2018-13302.json"}},{"package":{"name":"mythtv","ecosystem":"Ubuntu:18.04:LTS","purl":"pkg:deb/ubuntu/mythtv@2:29.1+fixes.20180414.329c235-0ubuntu3?arch=source&distro=bionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2:29.0+fixes.20170728.696806310a-0ubuntu1","2:29.0+fixes.20170728.696806310a-0ubuntu3","2:29.0+fixes.20170728.696806310a-0ubuntu4","2:29.0+fixes.20170728.696806310a-0ubuntu5","2:29.0+fixes.20170728.696806310a-0ubuntu6","2:29.0+fixes.20170728.696806310a-0ubuntu7","2:29.0+fixes.20170728.696806310a-0ubuntu8","2:29.1+fixes.20180220.9b7b962-0ubuntu2","2:29.1+fixes.20180220.9b7b962-0ubuntu3","2:29.1+fixes.20180414.329c235-0ubuntu3"],"ecosystem_specific":{"binaries":[{"binary_name":"libmyth","binary_version":"2:29.1+fixes.20180414.329c235-0ubuntu3"},{"binary_name":"libmyth-dev","binary_version":"2:29.1+fixes.20180414.329c235-0ubuntu3"},{"binary_name":"libmyth-python","binary_version":"2:29.1+fixes.20180414.329c235-0ubuntu3"},{"binary_name":"libmythtv-perl","binary_version":"2:29.1+fixes.20180414.329c235-0ubuntu3"},{"binary_name":"mytharchive","binary_version":"2:29.1+fixes.20180414.329c235-0ubuntu3"},{"binary_name":"mythbrowser","binary_version":"2:29.1+fixes.20180414.329c235-0ubuntu3"},{"binary_name":"mythgallery","binary_version":"2:29.1+fixes.20180414.329c235-0ubuntu3"},{"binary_name":"mythgame","binary_version":"2:29.1+fixes.20180414.329c235-0ubuntu3"},{"binary_name":"mythmusic","binary_version":"2:29.1+fixes.20180414.329c235-0ubuntu3"},{"binary_name":"mythnetvision","binary_version":"2:29.1+fixes.20180414.329c235-0ubuntu3"},{"binary_name":"mythnews","binary_version":"2:29.1+fixes.20180414.329c235-0ubuntu3"},{"binary_name":"mythplugins","binary_version":"2:29.1+fixes.20180414.329c235-0ubuntu3"},{"binary_name":"mythtv","binary_version":"2:29.1+fixes.20180414.329c235-0ubuntu3"},{"binary_name":"mythtv-backend","binary_version":"2:29.1+fixes.20180414.329c235-0ubuntu3"},{"binary_name":"mythtv-backend-master","binary_version":"2:29.1+fixes.20180414.329c235-0ubuntu3"},{"binary_name":"mythtv-common","binary_version":"2:29.1+fixes.20180414.329c235-0ubuntu3"},{"binary_name":"mythtv-database","binary_version":"2:29.1+fixes.20180414.329c235-0ubuntu3"},{"binary_name":"mythtv-frontend","binary_version":"2:29.1+fixes.20180414.329c235-0ubuntu3"},{"binary_name":"mythtv-theme-mythbuntu","binary_version":"2:29.1+fixes.20180414.329c235-0ubuntu3"},{"binary_name":"mythtv-transcode-utils","binary_version":"2:29.1+fixes.20180414.329c235-0ubuntu3"},{"binary_name":"mythweather","binary_version":"2:29.1+fixes.20180414.329c235-0ubuntu3"},{"binary_name":"mythweb","binary_version":"2:29.1+fixes.20180414.329c235-0ubuntu3"},{"binary_name":"mythzoneminder","binary_version":"2:29.1+fixes.20180414.329c235-0ubuntu3"},{"binary_name":"php-mythtv","binary_version":"2:29.1+fixes.20180414.329c235-0ubuntu3"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2018/UBUNTU-CVE-2018-13302.json"}},{"package":{"name":"gst-libav1.0","ecosystem":"Ubuntu:20.04:LTS","purl":"pkg:deb/ubuntu/gst-libav1.0@1.16.2-2?arch=source&distro=focal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.16.1-1","1.16.2-1","1.16.2-2"],"ecosystem_specific":{"binaries":[{"binary_name":"gstreamer1.0-libav","binary_version":"1.16.2-2"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2018/UBUNTU-CVE-2018-13302.json"}},{"package":{"name":"kino","ecosystem":"Ubuntu:20.04:LTS","purl":"pkg:deb/ubuntu/kino@1.3.4+dfsg0-1build1?arch=source&distro=focal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.3.4+dfsg0-1","1.3.4+dfsg0-1build1"],"ecosystem_specific":{"binaries":[{"binary_name":"kino","binary_version":"1.3.4+dfsg0-1build1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2018/UBUNTU-CVE-2018-13302.json"}},{"package":{"name":"mythtv","ecosystem":"Ubuntu:20.04:LTS","purl":"pkg:deb/ubuntu/mythtv@2:31.0+fixes.20200323.9579662cdc-0ubuntu1?arch=source&distro=focal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2:30.0+fixes.20190817.5cde0578d8-0ubuntu1","2:30.0+fixes.20190817.5cde0578d8-0ubuntu2","2:30.0+fixes.20190817.5cde0578d8-0ubuntu3","2:31.0+fixes.20200207.35cb9ed0c5-0ubuntu2","2:31.0+fixes.20200323.9579662cdc-0ubuntu1"],"ecosystem_specific":{"binaries":[{"binary_name":"libmyth","binary_version":"2:31.0+fixes.20200323.9579662cdc-0ubuntu1"},{"binary_name":"libmyth-dev","binary_version":"2:31.0+fixes.20200323.9579662cdc-0ubuntu1"},{"binary_name":"libmyth-python","binary_version":"2:31.0+fixes.20200323.9579662cdc-0ubuntu1"},{"binary_name":"libmythtv-perl","binary_version":"2:31.0+fixes.20200323.9579662cdc-0ubuntu1"},{"binary_name":"mytharchive","binary_version":"2:31.0+fixes.20200323.9579662cdc-0ubuntu1"},{"binary_name":"mythbrowser","binary_version":"2:31.0+fixes.20200323.9579662cdc-0ubuntu1"},{"binary_name":"mythgame","binary_version":"2:31.0+fixes.20200323.9579662cdc-0ubuntu1"},{"binary_name":"mythmusic","binary_version":"2:31.0+fixes.20200323.9579662cdc-0ubuntu1"},{"binary_name":"mythnews","binary_version":"2:31.0+fixes.20200323.9579662cdc-0ubuntu1"},{"binary_name":"mythplugins","binary_version":"2:31.0+fixes.20200323.9579662cdc-0ubuntu1"},{"binary_name":"mythtv","binary_version":"2:31.0+fixes.20200323.9579662cdc-0ubuntu1"},{"binary_name":"mythtv-backend","binary_version":"2:31.0+fixes.20200323.9579662cdc-0ubuntu1"},{"binary_name":"mythtv-backend-master","binary_version":"2:31.0+fixes.20200323.9579662cdc-0ubuntu1"},{"binary_name":"mythtv-common","binary_version":"2:31.0+fixes.20200323.9579662cdc-0ubuntu1"},{"binary_name":"mythtv-database","binary_version":"2:31.0+fixes.20200323.9579662cdc-0ubuntu1"},{"binary_name":"mythtv-frontend","binary_version":"2:31.0+fixes.20200323.9579662cdc-0ubuntu1"},{"binary_name":"mythtv-theme-mythbuntu","binary_version":"2:31.0+fixes.20200323.9579662cdc-0ubuntu1"},{"binary_name":"mythtv-transcode-utils","binary_version":"2:31.0+fixes.20200323.9579662cdc-0ubuntu1"},{"binary_name":"mythweather","binary_version":"2:31.0+fixes.20200323.9579662cdc-0ubuntu1"},{"binary_name":"mythweb","binary_version":"2:31.0+fixes.20200323.9579662cdc-0ubuntu1"},{"binary_name":"mythzoneminder","binary_version":"2:31.0+fixes.20200323.9579662cdc-0ubuntu1"},{"binary_name":"php-mythtv","binary_version":"2:31.0+fixes.20200323.9579662cdc-0ubuntu1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2018/UBUNTU-CVE-2018-13302.json"}},{"package":{"name":"chromium-browser","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/chromium-browser@1:85.0.4183.83-0ubuntu2.22.04.1?arch=source&distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1:85.0.4183.83-0ubuntu2","1:85.0.4183.83-0ubuntu2.22.04.1"],"ecosystem_specific":{"binaries":[{"binary_name":"chromium-browser","binary_version":"1:85.0.4183.83-0ubuntu2.22.04.1"},{"binary_name":"chromium-browser-l10n","binary_version":"1:85.0.4183.83-0ubuntu2.22.04.1"},{"binary_name":"chromium-chromedriver","binary_version":"1:85.0.4183.83-0ubuntu2.22.04.1"},{"binary_name":"chromium-codecs-ffmpeg","binary_version":"1:85.0.4183.83-0ubuntu2.22.04.1"},{"binary_name":"chromium-codecs-ffmpeg-extra","binary_version":"1:85.0.4183.83-0ubuntu2.22.04.1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2018/UBUNTU-CVE-2018-13302.json"}},{"package":{"name":"gst-libav1.0","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/gst-libav1.0@1.20.3-0ubuntu1?arch=source&distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.18.5-1","1.20.0-1","1.20.1-1","1.20.3-0ubuntu1"],"ecosystem_specific":{"binaries":[{"binary_name":"gstreamer1.0-libav","binary_version":"1.20.3-0ubuntu1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2018/UBUNTU-CVE-2018-13302.json"}},{"package":{"name":"kino","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/kino@1.3.4+dfsg0-1.1?arch=source&distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.3.4+dfsg0-1build2","1.3.4+dfsg0-1.1"],"ecosystem_specific":{"binaries":[{"binary_name":"kino","binary_version":"1.3.4+dfsg0-1.1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2018/UBUNTU-CVE-2018-13302.json"}},{"package":{"name":"mythtv","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/mythtv@2:32.0+fixes.20220325.f69ce764b7-0ubuntu1?arch=source&distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2:31.0+fixes.20200323.9579662cdc-0ubuntu9","2:31.0+fixes.20200323.9579662cdc-0ubuntu11","2:32.0+fixes.20220224.56275b303b-0ubuntu3","2:32.0+fixes.20220224.56275b303b-0ubuntu5","2:32.0+fixes.20220325.f69ce764b7-0ubuntu1"],"ecosystem_specific":{"binaries":[{"binary_name":"libmyth","binary_version":"2:32.0+fixes.20220325.f69ce764b7-0ubuntu1"},{"binary_name":"libmyth-dev","binary_version":"2:32.0+fixes.20220325.f69ce764b7-0ubuntu1"},{"binary_name":"libmyth-python","binary_version":"2:32.0+fixes.20220325.f69ce764b7-0ubuntu1"},{"binary_name":"libmythtv-perl","binary_version":"2:32.0+fixes.20220325.f69ce764b7-0ubuntu1"},{"binary_name":"mytharchive","binary_version":"2:32.0+fixes.20220325.f69ce764b7-0ubuntu1"},{"binary_name":"mythbrowser","binary_version":"2:32.0+fixes.20220325.f69ce764b7-0ubuntu1"},{"binary_name":"mythgame","binary_version":"2:32.0+fixes.20220325.f69ce764b7-0ubuntu1"},{"binary_name":"mythmusic","binary_version":"2:32.0+fixes.20220325.f69ce764b7-0ubuntu1"},{"binary_name":"mythnews","binary_version":"2:32.0+fixes.20220325.f69ce764b7-0ubuntu1"},{"binary_name":"mythplugins","binary_version":"2:32.0+fixes.20220325.f69ce764b7-0ubuntu1"},{"binary_name":"mythtv","binary_version":"2:32.0+fixes.20220325.f69ce764b7-0ubuntu1"},{"binary_name":"mythtv-backend","binary_version":"2:32.0+fixes.20220325.f69ce764b7-0ubuntu1"},{"binary_name":"mythtv-backend-master","binary_version":"2:32.0+fixes.20220325.f69ce764b7-0ubuntu1"},{"binary_name":"mythtv-common","binary_version":"2:32.0+fixes.20220325.f69ce764b7-0ubuntu1"},{"binary_name":"mythtv-database","binary_version":"2:32.0+fixes.20220325.f69ce764b7-0ubuntu1"},{"binary_name":"mythtv-frontend","binary_version":"2:32.0+fixes.20220325.f69ce764b7-0ubuntu1"},{"binary_name":"mythtv-theme-mythbuntu","binary_version":"2:32.0+fixes.20220325.f69ce764b7-0ubuntu1"},{"binary_name":"mythtv-transcode-utils","binary_version":"2:32.0+fixes.20220325.f69ce764b7-0ubuntu1"},{"binary_name":"mythweather","binary_version":"2:32.0+fixes.20220325.f69ce764b7-0ubuntu1"},{"binary_name":"mythweb","binary_version":"2:32.0+fixes.20220325.f69ce764b7-0ubuntu1"},{"binary_name":"mythzoneminder","binary_version":"2:32.0+fixes.20220325.f69ce764b7-0ubuntu1"},{"binary_name":"php-mythtv","binary_version":"2:32.0+fixes.20220325.f69ce764b7-0ubuntu1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2018/UBUNTU-CVE-2018-13302.json"}},{"package":{"name":"chromium-browser","ecosystem":"Ubuntu:24.04:LTS","purl":"pkg:deb/ubuntu/chromium-browser@2:1snap1-0ubuntu2?arch=source&distro=noble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1:85.0.4183.83-0ubuntu3","2:1snap1-0ubuntu1","2:1snap1-0ubuntu2"],"ecosystem_specific":{"binaries":[{"binary_name":"chromium-browser","binary_version":"2:1snap1-0ubuntu2"},{"binary_name":"chromium-browser-l10n","binary_version":"2:1snap1-0ubuntu2"},{"binary_name":"chromium-chromedriver","binary_version":"2:1snap1-0ubuntu2"},{"binary_name":"chromium-codecs-ffmpeg","binary_version":"2:1snap1-0ubuntu2"},{"binary_name":"chromium-codecs-ffmpeg-extra","binary_version":"2:1snap1-0ubuntu2"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2018/UBUNTU-CVE-2018-13302.json"}},{"package":{"name":"gst-libav1.0","ecosystem":"Ubuntu:24.04:LTS","purl":"pkg:deb/ubuntu/gst-libav1.0@1.24.1-1build1?arch=source&distro=noble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.22.5-1","1.22.6-1","1.22.7-1","1.22.8-1","1.22.10-1","1.24.1-1","1.24.1-1build1"],"ecosystem_specific":{"binaries":[{"binary_name":"gstreamer1.0-libav","binary_version":"1.24.1-1build1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2018/UBUNTU-CVE-2018-13302.json"}},{"package":{"name":"mythtv","ecosystem":"Ubuntu:24.04:LTS","purl":"pkg:deb/ubuntu/mythtv@2:34.0+fixes.20240210.e3e165a1-0ubuntu6?arch=source&distro=noble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2:33.0+fixes.20230210.026e506-0ubuntu0","2:33.0+fixes.20230210.026e506-0ubuntu2","2:33.0+fixes.20230210.026e506-0ubuntu3","2:33.0+fixes.20230210.026e506-0ubuntu4","2:33.0+fixes.20230210.026e506-0ubuntu5","2:34.0+fixes.20240210.e3e165a1-0ubuntu1","2:34.0+fixes.20240210.e3e165a1-0ubuntu4","2:34.0+fixes.20240210.e3e165a1-0ubuntu5","2:34.0+fixes.20240210.e3e165a1-0ubuntu6"],"ecosystem_specific":{"binaries":[{"binary_name":"libmyth","binary_version":"2:34.0+fixes.20240210.e3e165a1-0ubuntu6"},{"binary_name":"libmyth-dev","binary_version":"2:34.0+fixes.20240210.e3e165a1-0ubuntu6"},{"binary_name":"libmyth-python","binary_version":"2:34.0+fixes.20240210.e3e165a1-0ubuntu6"},{"binary_name":"libmythtv-perl","binary_version":"2:34.0+fixes.20240210.e3e165a1-0ubuntu6"},{"binary_name":"mytharchive","binary_version":"2:34.0+fixes.20240210.e3e165a1-0ubuntu6"},{"binary_name":"mythbrowser","binary_version":"2:34.0+fixes.20240210.e3e165a1-0ubuntu6"},{"binary_name":"mythgame","binary_version":"2:34.0+fixes.20240210.e3e165a1-0ubuntu6"},{"binary_name":"mythmusic","binary_version":"2:34.0+fixes.20240210.e3e165a1-0ubuntu6"},{"binary_name":"mythnews","binary_version":"2:34.0+fixes.20240210.e3e165a1-0ubuntu6"},{"binary_name":"mythplugins","binary_version":"2:34.0+fixes.20240210.e3e165a1-0ubuntu6"},{"binary_name":"mythtv","binary_version":"2:34.0+fixes.20240210.e3e165a1-0ubuntu6"},{"binary_name":"mythtv-backend","binary_version":"2:34.0+fixes.20240210.e3e165a1-0ubuntu6"},{"binary_name":"mythtv-backend-master","binary_version":"2:34.0+fixes.20240210.e3e165a1-0ubuntu6"},{"binary_name":"mythtv-common","binary_version":"2:34.0+fixes.20240210.e3e165a1-0ubuntu6"},{"binary_name":"mythtv-database","binary_version":"2:34.0+fixes.20240210.e3e165a1-0ubuntu6"},{"binary_name":"mythtv-frontend","binary_version":"2:34.0+fixes.20240210.e3e165a1-0ubuntu6"},{"binary_name":"mythtv-theme-mythbuntu","binary_version":"2:34.0+fixes.20240210.e3e165a1-0ubuntu6"},{"binary_name":"mythtv-transcode-utils","binary_version":"2:34.0+fixes.20240210.e3e165a1-0ubuntu6"},{"binary_name":"mythweather","binary_version":"2:34.0+fixes.20240210.e3e165a1-0ubuntu6"},{"binary_name":"mythweb","binary_version":"2:34.0+fixes.20240210.e3e165a1-0ubuntu6"},{"binary_name":"mythzoneminder","binary_version":"2:34.0+fixes.20240210.e3e165a1-0ubuntu6"},{"binary_name":"php-mythtv","binary_version":"2:34.0+fixes.20240210.e3e165a1-0ubuntu6"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2018/UBUNTU-CVE-2018-13302.json"}},{"package":{"name":"chromium-browser","ecosystem":"Ubuntu:25.10","purl":"pkg:deb/ubuntu/chromium-browser@2:1snap1-0ubuntu3?arch=source&distro=questing"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2:1snap1-0ubuntu3"],"ecosystem_specific":{"binaries":[{"binary_name":"chromium-browser","binary_version":"2:1snap1-0ubuntu3"},{"binary_name":"chromium-browser-l10n","binary_version":"2:1snap1-0ubuntu3"},{"binary_name":"chromium-chromedriver","binary_version":"2:1snap1-0ubuntu3"},{"binary_name":"chromium-codecs-ffmpeg","binary_version":"2:1snap1-0ubuntu3"},{"binary_name":"chromium-codecs-ffmpeg-extra","binary_version":"2:1snap1-0ubuntu3"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2018/UBUNTU-CVE-2018-13302.json"}},{"package":{"name":"gst-libav1.0","ecosystem":"Ubuntu:25.10","purl":"pkg:deb/ubuntu/gst-libav1.0@1.26.6-1?arch=source&distro=questing"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.26.0-1","1.26.1-1","1.26.2-1","1.26.3-1","1.26.4-1","1.26.5-1","1.26.6-1"],"ecosystem_specific":{"binaries":[{"binary_name":"gstreamer1.0-libav","binary_version":"1.26.6-1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2018/UBUNTU-CVE-2018-13302.json"}},{"package":{"name":"mythtv","ecosystem":"Ubuntu:25.10","purl":"pkg:deb/ubuntu/mythtv@2:35.0+fixes.20250302.f3f012aa3f-0ubuntu4?arch=source&distro=questing"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2:35.0+fixes.20250302.f3f012aa3f-0ubuntu3","2:35.0+fixes.20250302.f3f012aa3f-0ubuntu4"],"ecosystem_specific":{"binaries":[{"binary_name":"libmyth","binary_version":"2:35.0+fixes.20250302.f3f012aa3f-0ubuntu4"},{"binary_name":"libmyth-dev","binary_version":"2:35.0+fixes.20250302.f3f012aa3f-0ubuntu4"},{"binary_name":"libmyth-python","binary_version":"2:35.0+fixes.20250302.f3f012aa3f-0ubuntu4"},{"binary_name":"libmythtv-perl","binary_version":"2:35.0+fixes.20250302.f3f012aa3f-0ubuntu4"},{"binary_name":"mytharchive","binary_version":"2:35.0+fixes.20250302.f3f012aa3f-0ubuntu4"},{"binary_name":"mythbrowser","binary_version":"2:35.0+fixes.20250302.f3f012aa3f-0ubuntu4"},{"binary_name":"mythgame","binary_version":"2:35.0+fixes.20250302.f3f012aa3f-0ubuntu4"},{"binary_name":"mythmusic","binary_version":"2:35.0+fixes.20250302.f3f012aa3f-0ubuntu4"},{"binary_name":"mythnews","binary_version":"2:35.0+fixes.20250302.f3f012aa3f-0ubuntu4"},{"binary_name":"mythplugins","binary_version":"2:35.0+fixes.20250302.f3f012aa3f-0ubuntu4"},{"binary_name":"mythtv","binary_version":"2:35.0+fixes.20250302.f3f012aa3f-0ubuntu4"},{"binary_name":"mythtv-backend","binary_version":"2:35.0+fixes.20250302.f3f012aa3f-0ubuntu4"},{"binary_name":"mythtv-backend-master","binary_version":"2:35.0+fixes.20250302.f3f012aa3f-0ubuntu4"},{"binary_name":"mythtv-common","binary_version":"2:35.0+fixes.20250302.f3f012aa3f-0ubuntu4"},{"binary_name":"mythtv-database","binary_version":"2:35.0+fixes.20250302.f3f012aa3f-0ubuntu4"},{"binary_name":"mythtv-frontend","binary_version":"2:35.0+fixes.20250302.f3f012aa3f-0ubuntu4"},{"binary_name":"mythtv-theme-mythbuntu","binary_version":"2:35.0+fixes.20250302.f3f012aa3f-0ubuntu4"},{"binary_name":"mythtv-transcode-utils","binary_version":"2:35.0+fixes.20250302.f3f012aa3f-0ubuntu4"},{"binary_name":"mythweather","binary_version":"2:35.0+fixes.20250302.f3f012aa3f-0ubuntu4"},{"binary_name":"mythzoneminder","binary_version":"2:35.0+fixes.20250302.f3f012aa3f-0ubuntu4"},{"binary_name":"php-mythtv","binary_version":"2:35.0+fixes.20250302.f3f012aa3f-0ubuntu4"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2018/UBUNTU-CVE-2018-13302.json"}}],"schema_version":"1.7.3","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"},{"type":"Ubuntu","score":"medium"}]}