SB2017030126 - Multiple vulnerabilities in Libav
Published: March 1, 2017 Updated: August 8, 2020
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 8 secuirty vulnerabilities.
1) Input validation error (CVE-ID: CVE-2016-9819)
The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.
libavcodec/mpegvideo.c in libav 11.8 allows remote attackers to cause a denial of service (crash) via vectors involving left shift of a negative value.
2) Input validation error (CVE-ID: CVE-2016-9820)
The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.
libavcodec/mpegvideo_motion.c in libav 11.8 allows remote attackers to cause a denial of service (crash) via vectors involving left shift of a negative value.
3) Integer overflow (CVE-ID: CVE-2016-9821)
The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.
Integer overflow in libavcodec/mpegvideo_parser.c in libav 11.8 allows remote attackers to cause a denial of service (crash) via a crafted file.
4) Integer overflow (CVE-ID: CVE-2016-9822)
The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.
Integer overflow in libavcodec/mpeg12dec.c in libav 11.8 allows remote attackers to cause a denial of service (crash) via a crafted file.
5) Buffer overflow (CVE-ID: CVE-2016-9823)
The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.
libavcodec/x86/mpegvideo.c in libav 11.8 allows remote attackers to cause a denial of service (crash) via a crafted file.
6) Integer overflow (CVE-ID: CVE-2016-9824)
The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.
Integer overflow in libswscale/x86/swscale.c in libav 11.8 allows remote attackers to cause a denial of service (crash) via a crafted file.
7) Input validation error (CVE-ID: CVE-2016-9825)
The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.
libswscale/utils.c in libav 11.8 allows remote attackers to cause a denial of service (crash) via vectors involving left shift of a negative value.
8) Input validation error (CVE-ID: CVE-2016-9826)
The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.
libavcodec/ituh263dec.c in libav 11.8 allows remote attackers to cause a denial of service (crash) via vectors involving left shift of a negative value.
Remediation
Install update from vendor's website.