漏洞信息详情
FFmpeg 缓冲区错误漏洞
漏洞简介
FFmpeg是FFmpeg(Ffmpeg)团队的一套可录制、转换以及流化音视频的完整解决方案。
FFmpeg 4.3.1版本存在缓冲区错误漏洞,该漏洞源于计算何时执行memset零操作时出现了错误。
漏洞公告
目前厂商已发布升级补丁以修复漏洞,补丁获取链接:
https://github.com/FFmpeg/FFmpeg/commit/b0a8b40294ea212c1938348ff112ef1b9bf16bb3
参考网址
来源:MISC
链接:https://github.com/FFmpeg/FFmpeg/commit/b0a8b40294ea212c1938348ff112ef1b9bf16bb3
来源:MISC
链接:https://github.com/FFmpeg/FFmpeg/commit/3e5959b3457f7f1856d997261e6ac672bba49e8b
来源:MLIST
链接:https://lists.debian.org/debian-lts-announce/2021/01/msg00026.html
来源:GENTOO
链接:https://security.gentoo.org/glsa/202105-24
来源:DEBIAN
链接:https://www.debian.org/security/2021/dsa-4990
来源:MISC
链接:https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=26532
来源:www.cybersecurity-help.cz
链接:https://www.cybersecurity-help.cz/vdb/SB2021052640
来源:nvd.nist.gov
链接:https://nvd.nist.gov/vuln/detail/CVE-2020-35965
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.0336/
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.3592
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/162800/Gentoo-Linux-Security-Advisory-202105-24.html
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.3481
来源:vigilance.fr
链接:https://vigilance.fr/vulnerability/FFmpeg-memory-corruption-via-decode-frame-34440
受影响实体
暂无
补丁
- FFmpeg 缓冲区错误漏洞的修复措施<!--2021-1-3-->
还没有评论,来说两句吧...