SB2023013045 - SUSE update for ffmpeg
Published: January 30, 2023
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 2 secuirty vulnerabilities.
1) Division by zero (CVE-ID: CVE-2019-13390)
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.The vulnerability exists due to a divide-by-zero condition in the "adx_write_trailer" function in the "libavformat/rawenc.c" file. A remote attacker can trick the victim to open a specially crafted file and crash the affected application.
2) NULL pointer dereference (CVE-ID: CVE-2022-3341)
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a NULL pointer dereference error within the decode_main_header() function in libavformat/nutdec.c A remote attacker can trick the victim to open a specially crafted file and perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.