USN-6449-2: FFmpeg regression
15 November 2023
USN-6449-1 introduced a regression in FFmpeg
Releases
Packages
- ffmpeg - Tools for transcoding, streaming and playing of multimedia files
Details
USN-6449-1 fixed vulnerabilities in FFmpeg. Unfortunately that update
could introduce a regression in tools using an FFmpeg library, like VLC.
This updated fixes the problem. We apologize for the inconvenience.
Original advisory details:
It was discovered that FFmpeg incorrectly managed memory resulting
in a memory leak. An attacker could possibly use this issue to cause
a denial of service via application crash. This issue only
affected Ubuntu 18.04 LTS and Ubuntu 20.04 LTS. (CVE-2020-22038)
It was discovered that FFmpeg incorrectly handled certain input files,
leading to an integer overflow. An attacker could possibly use this issue
to cause a denial of service via application crash. This issue only
affected Ubuntu 20.04 LTS. (CVE-2020-20898, CVE-2021-38090,
CVE-2021-38091, CVE-2021-38092, CVE-2021-38093, CVE-2021-38094)
It was discovered that FFmpeg incorrectly managed memory, resulting in
a memory leak. If a user or automated system were tricked into
processing a specially crafted input file, a remote attacker could
possibly use this issue to cause a denial of service, or execute
arbitrary code. (CVE-2022-48434)
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 22.04
-
ffmpeg
-
7:4.4.2-0ubuntu0.22.04.1+esm3
Available with Ubuntu Pro
-
libavcodec-extra
-
7:4.4.2-0ubuntu0.22.04.1+esm3
Available with Ubuntu Pro
-
libavcodec-extra58
-
7:4.4.2-0ubuntu0.22.04.1+esm3
Available with Ubuntu Pro
-
libavcodec58
-
7:4.4.2-0ubuntu0.22.04.1+esm3
Available with Ubuntu Pro
-
libavdevice58
-
7:4.4.2-0ubuntu0.22.04.1+esm3
Available with Ubuntu Pro
-
libavfilter-extra
-
7:4.4.2-0ubuntu0.22.04.1+esm3
Available with Ubuntu Pro
-
libavfilter-extra7
-
7:4.4.2-0ubuntu0.22.04.1+esm3
Available with Ubuntu Pro
-
libavfilter7
-
7:4.4.2-0ubuntu0.22.04.1+esm3
Available with Ubuntu Pro
-
libavformat-extra
-
7:4.4.2-0ubuntu0.22.04.1+esm3
Available with Ubuntu Pro
-
libavformat-extra58
-
7:4.4.2-0ubuntu0.22.04.1+esm3
Available with Ubuntu Pro
-
libavformat58
-
7:4.4.2-0ubuntu0.22.04.1+esm3
Available with Ubuntu Pro
-
libavutil56
-
7:4.4.2-0ubuntu0.22.04.1+esm3
Available with Ubuntu Pro
-
libpostproc55
-
7:4.4.2-0ubuntu0.22.04.1+esm3
Available with Ubuntu Pro
-
libswresample3
-
7:4.4.2-0ubuntu0.22.04.1+esm3
Available with Ubuntu Pro
-
libswscale5
-
7:4.4.2-0ubuntu0.22.04.1+esm3
Available with Ubuntu Pro
Ubuntu 20.04
-
ffmpeg
-
7:4.2.7-0ubuntu0.1+esm4
Available with Ubuntu Pro
-
libavcodec-extra
-
7:4.2.7-0ubuntu0.1+esm4
Available with Ubuntu Pro
-
libavcodec-extra58
-
7:4.2.7-0ubuntu0.1+esm4
Available with Ubuntu Pro
-
libavcodec58
-
7:4.2.7-0ubuntu0.1+esm4
Available with Ubuntu Pro
-
libavdevice58
-
7:4.2.7-0ubuntu0.1+esm4
Available with Ubuntu Pro
-
libavfilter-extra
-
7:4.2.7-0ubuntu0.1+esm4
Available with Ubuntu Pro
-
libavfilter-extra7
-
7:4.2.7-0ubuntu0.1+esm4
Available with Ubuntu Pro
-
libavfilter7
-
7:4.2.7-0ubuntu0.1+esm4
Available with Ubuntu Pro
-
libavformat58
-
7:4.2.7-0ubuntu0.1+esm4
Available with Ubuntu Pro
-
libavresample4
-
7:4.2.7-0ubuntu0.1+esm4
Available with Ubuntu Pro
-
libavutil-dev
-
7:4.2.7-0ubuntu0.1+esm4
Available with Ubuntu Pro
-
libavutil56
-
7:4.2.7-0ubuntu0.1+esm4
Available with Ubuntu Pro
-
libpostproc55
-
7:4.2.7-0ubuntu0.1+esm4
Available with Ubuntu Pro
-
libswresample3
-
7:4.2.7-0ubuntu0.1+esm4
Available with Ubuntu Pro
-
libswscale5
-
7:4.2.7-0ubuntu0.1+esm4
Available with Ubuntu Pro
Ubuntu 18.04
-
ffmpeg
-
7:3.4.11-0ubuntu0.1+esm4
Available with Ubuntu Pro
-
libavcodec-extra
-
7:3.4.11-0ubuntu0.1+esm4
Available with Ubuntu Pro
-
libavcodec-extra57
-
7:3.4.11-0ubuntu0.1+esm4
Available with Ubuntu Pro
-
libavcodec57
-
7:3.4.11-0ubuntu0.1+esm4
Available with Ubuntu Pro
-
libavdevice-dev
-
7:3.4.11-0ubuntu0.1+esm4
Available with Ubuntu Pro
-
libavdevice57
-
7:3.4.11-0ubuntu0.1+esm4
Available with Ubuntu Pro
-
libavfilter-dev
-
7:3.4.11-0ubuntu0.1+esm4
Available with Ubuntu Pro
-
libavfilter-extra
-
7:3.4.11-0ubuntu0.1+esm4
Available with Ubuntu Pro
-
libavfilter-extra6
-
7:3.4.11-0ubuntu0.1+esm4
Available with Ubuntu Pro
-
libavfilter6
-
7:3.4.11-0ubuntu0.1+esm4
Available with Ubuntu Pro
-
libavformat57
-
7:3.4.11-0ubuntu0.1+esm4
Available with Ubuntu Pro
-
libavresample3
-
7:3.4.11-0ubuntu0.1+esm4
Available with Ubuntu Pro
-
libavutil-dev
-
7:3.4.11-0ubuntu0.1+esm4
Available with Ubuntu Pro
-
libavutil55
-
7:3.4.11-0ubuntu0.1+esm4
Available with Ubuntu Pro
-
libpostproc54
-
7:3.4.11-0ubuntu0.1+esm4
Available with Ubuntu Pro
-
libswresample2
-
7:3.4.11-0ubuntu0.1+esm4
Available with Ubuntu Pro
-
libswscale4
-
7:3.4.11-0ubuntu0.1+esm4
Available with Ubuntu Pro
In general, a standard system update will make all the necessary changes.