{"id":25593,"date":"2022-06-09T20:28:28","date_gmt":"2022-06-09T16:28:28","guid":{"rendered":"https:\/\/packetstormsecurity.com\/files\/167458\/USN-5472-1.txt"},"modified":"2022-06-14T11:46:56","modified_gmt":"2022-06-14T07:16:56","slug":"ubuntu-security-notice-usn-5472-1-ffmpeg","status":"publish","type":"post","link":"https:\/\/afaghhosting.net\/blog\/ubuntu-security-notice-usn-5472-1-ffmpeg\/","title":{"rendered":"Ubuntu Security Notice USN-5472-1 ffmpeg"},"content":{"rendered":"<p dir=\"ltr\">=========================================================================<br \/>\nUbuntu Security Notice USN-5472-1<br \/>\nJune 08, 2022<\/p>\n<p dir=\"ltr\">ffmpeg vulnerabilities<br \/>\n=========================================================================<br \/>\nA security issue affects these releases of Ubuntu and its derivatives:<\/p>\n<p dir=\"ltr\">&#8211; Ubuntu 22.04 LTS<br \/>\n&#8211; Ubuntu 21.10<br \/>\n&#8211; Ubuntu 20.04 LTS<br \/>\n&#8211; Ubuntu 18.04 LTS<\/p>\n<p dir=\"ltr\">Summary:<\/p>\n<p dir=\"ltr\">Several security issues were fixed in FFmpeg.<\/p>\n<p dir=\"ltr\">Software Description:<br \/>\n&#8211; ffmpeg: Tools for transcoding, streaming and playing of multimedia files<\/p>\n<p dir=\"ltr\">Details:<\/p>\n<p dir=\"ltr\">It was discovered that FFmpeg would attempt to divide by zero when using Linear<br \/>\nPredictive Coding (LPC) or AAC codecs. An attacker could possibly use this<br \/>\nissue to cause a denial of service. This issue only affected Ubuntu 18.04 LTS,<br \/>\nUbuntu 20.04 LTS and Ubuntu 21.10. (CVE-2020-20445, CVE-2020-20446,<br \/>\nCVE-2020-20453)<\/p>\n<p dir=\"ltr\">It was discovered that FFmpeg incorrectly handled certain input. An attacker<br \/>\ncould possibly use this issue to cause a denial of service. This issue only<br \/>\naffected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS and Ubuntu 21.10. (CVE-2020-20450)<\/p>\n<p dir=\"ltr\">It was discovered that FFmpeg incorrectly handled file conversion to APNG<br \/>\nformat. An attacker could possibly use this issue to cause a denial of<br \/>\nservice. This issue only affected Ubuntu 18.04 LTS and Ubuntu 20.04 LTS.<br \/>\n(CVE-2020-21041)<\/p>\n<p dir=\"ltr\">It was discovered that FFmpeg incorrectly handled remuxing RTP-hint tracks.<br \/>\nA remote attacker could possibly use this issue to execute arbitrary code.<br \/>\nThis issue only affected Ubuntu 18.04 LTS and Ubuntu 20.04 LTS.<br \/>\n(CVE-2020-21688)<\/p>\n<p dir=\"ltr\">It was discovered that FFmpeg incorrectly handled certain specially crafted<br \/>\nAVI files. An attacker could possibly use this issue to cause a denial of<br \/>\nservice. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS and<br \/>\nUbuntu 21.10. (CVE-2020-21697)<\/p>\n<p dir=\"ltr\">It was discovered that FFmpeg incorrectly handled writing MOV video tags. An<br \/>\nattacker could possibly use this issue to cause a denial of service, obtain<br \/>\nsensitive information or execute arbitrary code. This issue only affected<br \/>\nUbuntu 18.04 LTS, Ubuntu 20.04 LTS and Ubuntu 21.10. (CVE-2020-22015)<\/p>\n<p dir=\"ltr\">It was discovered that FFmpeg incorrectly handled writing MOV files. An<br \/>\nattacker could possibly use this issue to cause a denial of service or other<br \/>\nunspecified impact. This issue affected only Ubuntu 18.04 LTS. (CVE-2020-22016)<\/p>\n<p dir=\"ltr\">It was discovered that FFmpeg incorrectly handled memory when using certain<br \/>\nfilters. An attacker could possibly use this issue to cause a denial of service<br \/>\nor other unspecified impact. This issue only affected Ubuntu 18.04 LTS and<br \/>\nUbuntu 20.04 LTS. (CVE-2020-22017, CVE-2020-22020, CVE-2020-22022,<br \/>\nCVE-2020-22023, CVE-2022-22025, CVE-2020-22026, CVE-2020-22028, CVE-2020-22031,<br \/>\nCVE-2020-22032, CVE-2020-22034, CVE-2020-22036, CVE-2020-22042)<\/p>\n<p dir=\"ltr\">It was discovered that FFmpeg incorrectly handled memory when using certain<br \/>\nfilters. An attacker could possibly use this issue to cause a denial of service<br \/>\nor other unspecified impact. This issue only affected Ubuntu 18.04 LTS,<br \/>\nUbuntu 20.04 LTS and Ubuntu 21.10. (CVE-2020-22019, CVE-2020-22021,<br \/>\nCVE-2020-22033)<\/p>\n<p dir=\"ltr\">It was discovered that FFmpeg incorrectly handled memory when using certain<br \/>\nfilters. An attacker could possibly use this issue to cause a denial of service<br \/>\nor other unspecified impact. This issue only affected Ubuntu 21.10.<br \/>\n(CVE-2020-22027, CVE-2020-22029, CVE-2020-22030, CVE-2020-22035)<\/p>\n<p dir=\"ltr\">It was discovered that FFmpeg incorrectly handled certain specially crafted<br \/>\nJPEG files. An attacker could possibly use this issue to obtain sensitive<br \/>\ninformation. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS and<br \/>\nUbuntu 21.10. (CVE-2020-22037)<\/p>\n<p dir=\"ltr\">It was discovered that FFmpeg incorrectly performed calculations in EXR codec.<br \/>\nAn attacker could possibly use this issue to cause a denial of service. This<br \/>\nissue only affected Ubuntu 18.04 LTS and Ubuntu 20.04 LTS. (CVE-2020-35965)<\/p>\n<p dir=\"ltr\">It was discovered that FFmpeg did not verify return values of functions<br \/>\ninit_vlc and init_get_bits. An attacker could possibly use this issue to cause<br \/>\na denial of service or other unspecified impact. This issue only affected<br \/>\nUbuntu 18.04 LTS, Ubuntu 20.04 LTS and Ubuntu 21.10. (CVE-2021-38114,<br \/>\nCVE-2021-38171)<\/p>\n<p dir=\"ltr\">It was discovered that FFmpeg incorrectly handled certain specially crafted<br \/>\nfiles. An attacker could possibly use this issue to cause a denial of service.<br \/>\nThis issue only affected Ubuntu 21.10 and Ubuntu 22.04 LTS. (CVE-2022-1475)<\/p>\n<p dir=\"ltr\">Update instructions:<\/p>\n<p dir=\"ltr\">The problem can be corrected by updating your system to the following<br \/>\npackage versions:<\/p>\n<p dir=\"ltr\">Ubuntu 22.04 LTS:<br \/>\nffmpeg 7:4.4.2-0ubuntu0.22.04.1<br \/>\nlibavcodec-extra58 7:4.4.2-0ubuntu0.22.04.1<br \/>\nlibavcodec58 7:4.4.2-0ubuntu0.22.04.1<br \/>\nlibavdevice58 7:4.4.2-0ubuntu0.22.04.1<br \/>\nlibavfilter-extra7 7:4.4.2-0ubuntu0.22.04.1<br \/>\nlibavfilter7 7:4.4.2-0ubuntu0.22.04.1<br \/>\nlibavformat-extra58 7:4.4.2-0ubuntu0.22.04.1<br \/>\nlibavformat58 7:4.4.2-0ubuntu0.22.04.1<br \/>\nlibavutil56 7:4.4.2-0ubuntu0.22.04.1<br \/>\nlibpostproc55 7:4.4.2-0ubuntu0.22.04.1<br \/>\nlibswresample3 7:4.4.2-0ubuntu0.22.04.1<br \/>\nlibswscale5 7:4.4.2-0ubuntu0.22.04.1<\/p>\n<p dir=\"ltr\">Ubuntu 21.10:<br \/>\nffmpeg 7:4.4.2-0ubuntu0.21.10.1<br \/>\nlibavcodec-extra58 7:4.4.2-0ubuntu0.21.10.1<br \/>\nlibavcodec58 7:4.4.2-0ubuntu0.21.10.1<br \/>\nlibavdevice58 7:4.4.2-0ubuntu0.21.10.1<br \/>\nlibavfilter-extra7 7:4.4.2-0ubuntu0.21.10.1<br \/>\nlibavfilter7 7:4.4.2-0ubuntu0.21.10.1<br \/>\nlibavformat-extra58 7:4.4.2-0ubuntu0.21.10.1<br \/>\nlibavformat58 7:4.4.2-0ubuntu0.21.10.1<br \/>\nlibavutil56 7:4.4.2-0ubuntu0.21.10.1<br \/>\nlibpostproc55 7:4.4.2-0ubuntu0.21.10.1<br \/>\nlibswresample3 7:4.4.2-0ubuntu0.21.10.1<br \/>\nlibswscale5 7:4.4.2-0ubuntu0.21.10.1<\/p>\n<p dir=\"ltr\">Ubuntu 20.04 LTS:<br \/>\nffmpeg 7:4.2.7-0ubuntu0.1<br \/>\nlibavcodec-extra58 7:4.2.7-0ubuntu0.1<br \/>\nlibavcodec58 7:4.2.7-0ubuntu0.1<br \/>\nlibavdevice58 7:4.2.7-0ubuntu0.1<br \/>\nlibavfilter-extra7 7:4.2.7-0ubuntu0.1<br \/>\nlibavfilter7 7:4.2.7-0ubuntu0.1<br \/>\nlibavformat58 7:4.2.7-0ubuntu0.1<br \/>\nlibavresample4 7:4.2.7-0ubuntu0.1<br \/>\nlibavutil56 7:4.2.7-0ubuntu0.1<br \/>\nlibpostproc55 7:4.2.7-0ubuntu0.1<br \/>\nlibswresample3 7:4.2.7-0ubuntu0.1<br \/>\nlibswscale5 7:4.2.7-0ubuntu0.1<\/p>\n<p dir=\"ltr\">Ubuntu 18.04 LTS:<br \/>\nffmpeg 7:3.4.11-0ubuntu0.1<br \/>\nlibavcodec-extra57 7:3.4.11-0ubuntu0.1<br \/>\nlibavcodec57 7:3.4.11-0ubuntu0.1<br \/>\nlibavdevice57 7:3.4.11-0ubuntu0.1<br \/>\nlibavfilter-extra6 7:3.4.11-0ubuntu0.1<br \/>\nlibavfilter6 7:3.4.11-0ubuntu0.1<br \/>\nlibavformat57 7:3.4.11-0ubuntu0.1<br \/>\nlibavresample3 7:3.4.11-0ubuntu0.1<br \/>\nlibavutil55 7:3.4.11-0ubuntu0.1<br \/>\nlibpostproc54 7:3.4.11-0ubuntu0.1<br \/>\nlibswresample2 7:3.4.11-0ubuntu0.1<br \/>\nlibswscale4 7:3.4.11-0ubuntu0.1<\/p>\n<p dir=\"ltr\">This update uses a new upstream release, which includes additional bug<br \/>\nfixes. In general, a standard system update will make all the necessary<br \/>\nchanges.<\/p>\n<p dir=\"ltr\">References:<br \/>\nhttps:\/\/ubuntu.com\/security\/notices\/USN-5472-1<br \/>\nCVE-2020-20445, CVE-2020-20446, CVE-2020-20450, CVE-2020-20453,<br \/>\nCVE-2020-21041, CVE-2020-21688, CVE-2020-21697, CVE-2020-22015,<br \/>\nCVE-2020-22016, CVE-2020-22017, CVE-2020-22019, CVE-2020-22020,<br \/>\nCVE-2020-22021, CVE-2020-22022, CVE-2020-22023, CVE-2020-22025,<br \/>\nCVE-2020-22026, CVE-2020-22027, CVE-2020-22028, CVE-2020-22029,<br \/>\nCVE-2020-22030, CVE-2020-22031, CVE-2020-22032, CVE-2020-22033,<br \/>\nCVE-2020-22034, CVE-2020-22035, CVE-2020-22036, CVE-2020-22037,<br \/>\nCVE-2020-22042, CVE-2020-35965, CVE-2021-38114, CVE-2021-38171,<br \/>\nCVE-2021-38291, CVE-2022-1475<\/p>\n<p dir=\"ltr\">Package Information:<br \/>\nhttps:\/\/launchpad.net\/ubuntu\/+source\/ffmpeg\/7:4.4.2-0ubuntu0.22.04.1<br \/>\nhttps:\/\/launchpad.net\/ubuntu\/+source\/ffmpeg\/7:4.4.2-0ubuntu0.21.10.1<br \/>\nhttps:\/\/launchpad.net\/ubuntu\/+source\/ffmpeg\/7:4.2.7-0ubuntu0.1<br \/>\nhttps:\/\/launchpad.net\/ubuntu\/+source\/ffmpeg\/7:3.4.11-0ubuntu0.1<\/p>\n","protected":false},"excerpt":{"rendered":"<p>========================================================================= Ubuntu Security Notice USN-5472-1 June 08, 2022 ffmpeg vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: &#8211; Ubuntu 22.04 LTS &#8211; Ubuntu 21.10 &#8211; Ubuntu 20.04 LTS &#8211; Ubuntu 18.04 LTS Summary: Several security issues were fixed in FFmpeg. Software Description: &#8211; ffmpeg: Tools for transcoding, streaming and playing &hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[26],"tags":[],"class_list":["post-25593","post","type-post","status-publish","format-standard","hentry","category-vulnerability"],"_links":{"self":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/25593","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/comments?post=25593"}],"version-history":[{"count":0,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/25593\/revisions"}],"wp:attachment":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/media?parent=25593"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/categories?post=25593"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/tags?post=25593"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}