USN-6449-1: FFmpeg vulnerabilities

Publication date

24 October 2023

Overview

Several security issues were fixed in FFmpeg.


Packages

  • ffmpeg - Tools for transcoding, streaming and playing of multimedia files

Details

It was discovered that FFmpeg incorrectly managed memory resulting
in a memory leak. An attacker could possibly use this issue to cause
a denial of service via application crash. This issue only
affected Ubuntu 18.04 LTS and Ubuntu 20.04 LTS. (CVE-2020-22038)

It was discovered that FFmpeg incorrectly handled certain input files,
leading to an integer overflow. An attacker could possibly use this issue
to cause a denial of service via application crash. This issue only
affected Ubuntu 20.04 LTS. (CVE-2020-20898, CVE-2021-38090,
CVE-2021-38091, CVE-2021-38092, CVE-2021-38093, CVE-2021-38094)

It was discovered that FFmpeg incorrectly managed memory, resulting in
a...

It was discovered that FFmpeg incorrectly managed memory resulting
in a memory leak. An attacker could possibly use this issue to cause
a denial of service via application crash. This issue only
affected Ubuntu 18.04 LTS and Ubuntu 20.04 LTS. (CVE-2020-22038)

It was discovered that FFmpeg incorrectly handled certain input files,
leading to an integer overflow. An attacker could possibly use this issue
to cause a denial of service via application crash. This issue only
affected Ubuntu 20.04 LTS. (CVE-2020-20898, CVE-2021-38090,
CVE-2021-38091, CVE-2021-38092, CVE-2021-38093, CVE-2021-38094)

It was discovered that FFmpeg incorrectly managed memory, resulting in
a memory leak. If a user or automated system were tricked into
processing a specially crafted input file, a remote attacker could
possibly use this issue to cause a denial of service, or execute
arbitrary code. (CVE-2022-48434)


Update instructions

In general, a standard system update will make all the necessary changes.

Learn more about how to get the fixes.

The problem can be corrected by updating your system to the following package versions:

Ubuntu Release Package Version
22.04 jammy ffmpeg –  7:4.4.2-0ubuntu0.22.04.1+esm2  
libavcodec-extra –  7:4.4.2-0ubuntu0.22.04.1+esm2  
libavcodec-extra58 –  7:4.4.2-0ubuntu0.22.04.1+esm2  
libavcodec58 –  7:4.4.2-0ubuntu0.22.04.1+esm2  
libavdevice58 –  7:4.4.2-0ubuntu0.22.04.1+esm2  
libavfilter-extra –  7:4.4.2-0ubuntu0.22.04.1+esm2  
libavfilter-extra7 –  7:4.4.2-0ubuntu0.22.04.1+esm2  
libavfilter7 –  7:4.4.2-0ubuntu0.22.04.1+esm2  
libavformat-extra –  7:4.4.2-0ubuntu0.22.04.1+esm2  
libavformat-extra58 –  7:4.4.2-0ubuntu0.22.04.1+esm2  
libavformat58 –  7:4.4.2-0ubuntu0.22.04.1+esm2  
libavutil56 –  7:4.4.2-0ubuntu0.22.04.1+esm2  
libpostproc55 –  7:4.4.2-0ubuntu0.22.04.1+esm2  
libswresample3 –  7:4.4.2-0ubuntu0.22.04.1+esm2  
libswscale-dev –  7:4.4.2-0ubuntu0.22.04.1+esm2  
libswscale5 –  7:4.4.2-0ubuntu0.22.04.1+esm2  
20.04 focal ffmpeg –  7:4.2.7-0ubuntu0.1+esm3  
libavcodec-extra –  7:4.2.7-0ubuntu0.1+esm3  
libavcodec-extra58 –  7:4.2.7-0ubuntu0.1+esm3  
libavcodec58 –  7:4.2.7-0ubuntu0.1+esm3  
libavdevice58 –  7:4.2.7-0ubuntu0.1+esm3  
libavfilter-extra –  7:4.2.7-0ubuntu0.1+esm3  
libavfilter-extra7 –  7:4.2.7-0ubuntu0.1+esm3  
libavfilter7 –  7:4.2.7-0ubuntu0.1+esm3  
libavformat58 –  7:4.2.7-0ubuntu0.1+esm3  
libavresample4 –  7:4.2.7-0ubuntu0.1+esm3  
libavutil56 –  7:4.2.7-0ubuntu0.1+esm3  
libpostproc55 –  7:4.2.7-0ubuntu0.1+esm3  
libswresample3 –  7:4.2.7-0ubuntu0.1+esm3  
libswscale5 –  7:4.2.7-0ubuntu0.1+esm3  
18.04 bionic ffmpeg –  7:3.4.11-0ubuntu0.1+esm3  
libavcodec-extra –  7:3.4.11-0ubuntu0.1+esm3  
libavcodec-extra57 –  7:3.4.11-0ubuntu0.1+esm3  
libavcodec57 –  7:3.4.11-0ubuntu0.1+esm3  
libavdevice57 –  7:3.4.11-0ubuntu0.1+esm3  
libavfilter-extra –  7:3.4.11-0ubuntu0.1+esm3  
libavfilter-extra6 –  7:3.4.11-0ubuntu0.1+esm3  
libavfilter6 –  7:3.4.11-0ubuntu0.1+esm3  
libavformat57 –  7:3.4.11-0ubuntu0.1+esm3  
libavresample3 –  7:3.4.11-0ubuntu0.1+esm3  
libavutil55 –  7:3.4.11-0ubuntu0.1+esm3  
libpostproc54 –  7:3.4.11-0ubuntu0.1+esm3  
libswresample2 –  7:3.4.11-0ubuntu0.1+esm3  
libswscale4 –  7:3.4.11-0ubuntu0.1+esm3  

Reduce your security exposure

Ubuntu Pro provides ten-year security coverage to 25,000+ packages in Main and Universe repositories, and it is free for up to five machines.


Have additional questions?

Talk to a member of the team ›