[CVE-2008-3230] ffmpeg crash in lavf demuxer via a crafted GIF file

Bug #253767 reported by Till Ulen
252
Affects Status Importance Assigned to Milestone
FFmpeg
Fix Released
Unknown
ffmpeg-debian (Debian)
Fix Released
Unknown
ffmpeg-debian (Ubuntu)
Fix Released
Undecided
Unassigned

Bug Description

Binary package hint: ffmpeg

CVE-2008-3230 description:

"The ffmpeg lavf demuxer allows user-assisted attackers to cause a denial of service (application crash) via a crafted GIF file, possibly related to gstreamer, as demonstrated by lol-giftopnm.gif."

http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3230

More information is available in the referenced bugs (see).

CVE References

Revision history for this message
Till Ulen (tillulen) wrote :

Hmm, I can't add a reference to the Gnome bug, so I'll paste it here along with another link:

http://bugzilla.gnome.org/show_bug.cgi?id=542643
http://www.openwall.com/lists/oss-security/2008/07/13/3

Changed in ffmpeg:
status: Unknown → Incomplete
Revision history for this message
Reinhard Tartler (siretart) wrote :

After reading the upstream bug report, this bug is more or less confirmed upstream. A patch is still to be written, though

Changed in ffmpeg:
status: New → Triaged
Changed in ffmpeg-debian:
status: Unknown → New
Revision history for this message
Launchpad Janitor (janitor) wrote :

This bug was fixed in the package ffmpeg-debian - 3:0.svn20090119-1ubuntu1

---------------
ffmpeg-debian (3:0.svn20090119-1ubuntu1) jaunty; urgency=low

  * merge from debian. LP: #318501
  * new version fixes CVE-2008-3230, LP: #253767

 -- Reinhard Tartler <email address hidden> Tue, 20 Jan 2009 09:20:53 +0100

Changed in ffmpeg-debian:
status: Triaged → Fix Released
Changed in ffmpeg:
status: Incomplete → Fix Released
Changed in ffmpeg-debian (Debian):
status: New → Fix Released
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.