{"id":"openSUSE-SU-2019:1066-1","summary":"Security update for ffmpeg-4","details":"This update for ffmpeg-4 to version 4.0.2 fixes the following issues:\n\nThese security issues were fixed:\n\n- CVE-2018-15822: The flv_write_packet function did not check for an empty\n  audio packet, leading to an assertion failure and DoS (bsc#1105869).\n- CVE-2018-13300: An improper argument passed to the avpriv_request_sample\n  function may have triggered an out-of-array read while converting a crafted AVI\n  file to MPEG4, leading to a denial of service and possibly an information\n  disclosure (bsc#1100348).\n\nThese non-security issues were fixed:\n\n- Enable webvtt encoders and decoders (boo#1092241).\n- Build codec2 encoder and decoder, add libcodec2 to\n  enable_decoders and enable_encoders.\n- Enable mpeg 1 and 2 encoders.\n\nThis update was imported from the openSUSE:Leap:15.0:Update update project.","modified":"2026-03-11T07:32:03.941040Z","published":"2019-03-28T05:49:45Z","related":["CVE-2018-13300","CVE-2018-15822"],"upstream":["CVE-2018-13300","CVE-2018-15822"],"references":[{"type":"ADVISORY","url":"https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/5JFIYYRNOGYLGMC55GONWEFOZJ5LAS7T/#5JFIYYRNOGYLGMC55GONWEFOZJ5LAS7T"},{"type":"REPORT","url":"https://bugzilla.suse.com/1092241"},{"type":"REPORT","url":"https://bugzilla.suse.com/1100348"},{"type":"REPORT","url":"https://bugzilla.suse.com/1105869"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-13300"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-15822"}],"affected":[{"package":{"name":"ffmpeg-4","ecosystem":"SUSE:Package Hub 15","purl":"pkg:rpm/suse/ffmpeg-4&distro=SUSE%20Package%20Hub%2015"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.0.2-bp150.21.1"}]}],"ecosystem_specific":{"binaries":[{"libavformat58":"4.0.2-bp150.21.1","libswscale5":"4.0.2-bp150.21.1","ffmpeg-4-libavformat-devel":"4.0.2-bp150.21.1","ffmpeg-4-libavutil-devel":"4.0.2-bp150.21.1","ffmpeg-4-libswresample-devel":"4.0.2-bp150.21.1","libavcodec58-64bit":"4.0.2-bp150.21.1","libavcodec58":"4.0.2-bp150.21.1","libavfilter7":"4.0.2-bp150.21.1","libavresample4":"4.0.2-bp150.21.1","libavutil56-64bit":"4.0.2-bp150.21.1","ffmpeg-4-libavcodec-devel":"4.0.2-bp150.21.1","ffmpeg-4-libavresample-devel":"4.0.2-bp150.21.1","ffmpeg-4-libpostproc-devel":"4.0.2-bp150.21.1","ffmpeg-4-libswscale-devel":"4.0.2-bp150.21.1","libavdevice58-64bit":"4.0.2-bp150.21.1","libavdevice58":"4.0.2-bp150.21.1","libpostproc55-64bit":"4.0.2-bp150.21.1","libswscale5-64bit":"4.0.2-bp150.21.1","ffmpeg-4-libavdevice-devel":"4.0.2-bp150.21.1","libavformat58-64bit":"4.0.2-bp150.21.1","libavresample4-64bit":"4.0.2-bp150.21.1","libavutil56":"4.0.2-bp150.21.1","libpostproc55":"4.0.2-bp150.21.1","libswresample3-64bit":"4.0.2-bp150.21.1","libswresample3":"4.0.2-bp150.21.1","ffmpeg-4-libavfilter-devel":"4.0.2-bp150.21.1","ffmpeg-4-private-devel":"4.0.2-bp150.21.1","libavfilter7-64bit":"4.0.2-bp150.21.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2019:1066-1.json"}}],"schema_version":"1.7.5"}