Your submission was sent successfully! Close

CVE-2014-8548

Published: 5 November 2014

Off-by-one error in libavcodec/smc.c in FFmpeg before 2.4.2 allows remote attackers to cause a denial of service (out-of-bounds access) or possibly have unspecified other impact via crafted Quicktime Graphics (aka SMC) video data.

Priority

Medium

Status

Package Release Status
ffmpeg
Launchpad, Ubuntu, Debian
artful Not vulnerable
(7:2.5.4-1)
bionic Not vulnerable
(7:2.5.4-1)
lucid Ignored
(reached end-of-life)
precise Does not exist

trusty Does not exist

upstream Needs triage

utopic Does not exist

vivid Not vulnerable
(7:2.5.4-1)
wily Not vulnerable
(7:2.5.4-1)
xenial Not vulnerable
(7:2.5.4-1)
yakkety Not vulnerable
(7:2.5.4-1)
zesty Not vulnerable
(7:2.5.4-1)
Patches:
upstream: http://git.videolan.org/?p=ffmpeg.git;a=commit;h=c727401aa9d62335e89d118a5b4e202edf39d905


libav
Launchpad, Ubuntu, Debian
artful Does not exist

bionic Does not exist

lucid Does not exist

precise Does not exist
(precise was released [4:0.8.17-0ubuntu0.12.04.1])
trusty Does not exist
(trusty was released [6:9.18-0ubuntu0.14.04.1])
upstream
Released (0.8.17,11.2,10.6,9.18)
utopic Ignored
(reached end-of-life)
vivid Not vulnerable
(6:11.2-1)
wily Does not exist

xenial Does not exist

yakkety Does not exist

zesty Does not exist

Patches:

upstream: https://git.libav.org/?p=libav.git;a=commit;h=d423dd72be451462c6fb1cbbe313bed0194001ab
upstream: https://git.libav.org/?p=libav.git;a=commit;h=a331e11906b196c9a00f5ffbc45d80fcd7fe8423 (0.8)
mplayer
Launchpad, Ubuntu, Debian
artful Ignored
(reached end-of-life)
bionic Not vulnerable
(code not present)
lucid Ignored
(reached end-of-life)
precise Does not exist
(precise was needed)
trusty Does not exist
(trusty was not-affected [uses system ffmpeg])
upstream Needs triage

utopic Does not exist

vivid Does not exist

wily Does not exist

xenial Not vulnerable
(code not present)
yakkety Ignored
(reached end-of-life)
zesty Ignored
(reached end-of-life)