Upstream information

CVE-2015-5479 at MITRE

Description

The ff_h263_decode_mba function in libavcodec/ituh263dec.c in Libav before 11.5 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a file with crafted dimensions.

SUSE information

Overall state of this security issue: Does not affect SUSE products

This issue is currently rated as having moderate severity.

CVSS v2 Scores
  National Vulnerability Database
Base Score 4.3
Vector AV:N/AC:M/Au:N/C:N/I:N/A:P
Access Vector Network
Access Complexity Medium
Authentication None
Confidentiality Impact None
Integrity Impact None
Availability Impact Partial
SUSE Bugzilla entry: 949760

SUSE Security Advisories:

List of released packages

Product(s) Fixed package version(s) References
openSUSE Leap 42.1
  • libav >= 11.4-5.1
  • libav-debugsource >= 11.4-5.1
  • libav-tools >= 11.4-5.1
  • libav-tools-debuginfo >= 11.4-5.1
  • libavcodec-libav-devel >= 11.4-5.1
  • libavcodec-libav56 >= 11.4-5.1
  • libavcodec-libav56-debuginfo >= 11.4-5.1
  • libavdevice-libav-devel >= 11.4-5.1
  • libavdevice-libav55 >= 11.4-5.1
  • libavdevice-libav55-debuginfo >= 11.4-5.1
  • libavfilter-libav-devel >= 11.4-5.1
  • libavfilter-libav5 >= 11.4-5.1
  • libavfilter-libav5-debuginfo >= 11.4-5.1
  • libavformat-libav-devel >= 11.4-5.1
  • libavformat-libav56 >= 11.4-5.1
  • libavformat-libav56-debuginfo >= 11.4-5.1
  • libavresample-libav-devel >= 11.4-5.1
  • libavresample-libav2 >= 11.4-5.1
  • libavresample-libav2-debuginfo >= 11.4-5.1
  • libavutil-libav-devel >= 11.4-5.1
  • libavutil-libav54 >= 11.4-5.1
  • libavutil-libav54-debuginfo >= 11.4-5.1
  • libswscale-libav-devel >= 11.4-5.1
  • libswscale-libav3 >= 11.4-5.1
  • libswscale-libav3-debuginfo >= 11.4-5.1
Patchnames:
openSUSE-2016-779