SB2018042111 - Assertion violation in ffmpeg (Alpine package)
Published: April 21, 2018
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Assertion violation (CVE-ID: CVE-2018-12458)
The vulnerability allows a remote attacker to cause DoS condition on the target system.
The vulnerability exists due to improper integer type in the mpeg4_encode_gop_header function in libavcodec/mpeg4videoenc.c. A remote attacker can supply specially crafted AVI file to MPEG4, trick the victim into converting it, trigger assertion violation and cause the service to crash.
Remediation
Install update from vendor's website.
References
- https://git.alpinelinux.org/aports/commit/?id=d8d38dabc6e30c901eb6bd6627d8337849d7c041
- https://git.alpinelinux.org/aports/commit/?id=cf78a820406ae4481e937bc2fba252ff79c89a09
- https://git.alpinelinux.org/aports/commit/?id=859fd99d06049c009c8b745626511cd681061a99
- https://git.alpinelinux.org/aports/commit/?id=244b8239305a7fb24f4d98be5abb84bda770afe7
- https://git.alpinelinux.org/aports/commit/?id=2a92300f12bdc3ed7fc960459e6b5a37868da059
- https://git.alpinelinux.org/aports/commit/?id=67e1fa48160c4e435007390d685bdfacd84ea1f0