The movreaddref function in libavformat/mov.c in Libav before 11.7 and FFmpeg before 0.11 allows remote attackers to cause a denial of service (memory corruption) or execute arbitrary code via the entries value in a dref box in an MP4 file.
{ "availability": "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "6:9.20-0ubuntu0.14.04.1+esm1", "binary_name": "libav-dbg" }, { "binary_version": "6:9.20-0ubuntu0.14.04.1+esm1", "binary_name": "libav-doc" }, { "binary_version": "6:9.20-0ubuntu0.14.04.1+esm1", "binary_name": "libav-tools" }, { "binary_version": "6:9.20-0ubuntu0.14.04.1+esm1", "binary_name": "libav-tools-dbgsym" }, { "binary_version": "6:9.20-0ubuntu0.14.04.1+esm1", "binary_name": "libavcodec-dev" }, { "binary_version": "6:9.20-0ubuntu0.14.04.1+esm1", "binary_name": "libavcodec-extra" }, { "binary_version": "6:9.20-0ubuntu0.14.04.1+esm1", "binary_name": "libavcodec-extra-54" }, { "binary_version": "6:9.20-0ubuntu0.14.04.1+esm1", "binary_name": "libavcodec-extra-54-dbgsym" }, { "binary_version": "6:9.20-0ubuntu0.14.04.1+esm1", "binary_name": "libavcodec54" }, { "binary_version": "6:9.20-0ubuntu0.14.04.1+esm1", "binary_name": "libavcodec54-dbgsym" }, { "binary_version": "6:9.20-0ubuntu0.14.04.1+esm1", "binary_name": "libavdevice-dev" }, { "binary_version": "6:9.20-0ubuntu0.14.04.1+esm1", "binary_name": "libavdevice-extra-53" }, { "binary_version": "6:9.20-0ubuntu0.14.04.1+esm1", "binary_name": "libavdevice53" }, { "binary_version": "6:9.20-0ubuntu0.14.04.1+esm1", "binary_name": "libavdevice53-dbgsym" }, { "binary_version": "6:9.20-0ubuntu0.14.04.1+esm1", "binary_name": "libavfilter-dev" }, { "binary_version": "6:9.20-0ubuntu0.14.04.1+esm1", "binary_name": "libavfilter-extra-3" }, { "binary_version": "6:9.20-0ubuntu0.14.04.1+esm1", "binary_name": "libavfilter3" }, { "binary_version": "6:9.20-0ubuntu0.14.04.1+esm1", "binary_name": "libavfilter3-dbgsym" }, { "binary_version": "6:9.20-0ubuntu0.14.04.1+esm1", "binary_name": "libavformat-dev" }, { "binary_version": "6:9.20-0ubuntu0.14.04.1+esm1", "binary_name": "libavformat-extra-54" }, { "binary_version": "6:9.20-0ubuntu0.14.04.1+esm1", "binary_name": "libavformat54" }, { "binary_version": "6:9.20-0ubuntu0.14.04.1+esm1", "binary_name": "libavformat54-dbgsym" }, { "binary_version": "6:9.20-0ubuntu0.14.04.1+esm1", "binary_name": "libavresample-dev" }, { "binary_version": "6:9.20-0ubuntu0.14.04.1+esm1", "binary_name": "libavresample1" }, { "binary_version": "6:9.20-0ubuntu0.14.04.1+esm1", "binary_name": "libavresample1-dbgsym" }, { "binary_version": "6:9.20-0ubuntu0.14.04.1+esm1", "binary_name": "libavutil-dev" }, { "binary_version": "6:9.20-0ubuntu0.14.04.1+esm1", "binary_name": "libavutil-extra-52" }, { "binary_version": "6:9.20-0ubuntu0.14.04.1+esm1", "binary_name": "libavutil52" }, { "binary_version": "6:9.20-0ubuntu0.14.04.1+esm1", "binary_name": "libavutil52-dbgsym" }, { "binary_version": "6:9.20-0ubuntu0.14.04.1+esm1", "binary_name": "libswscale-dev" }, { "binary_version": "6:9.20-0ubuntu0.14.04.1+esm1", "binary_name": "libswscale-extra-2" }, { "binary_version": "6:9.20-0ubuntu0.14.04.1+esm1", "binary_name": "libswscale2" }, { "binary_version": "6:9.20-0ubuntu0.14.04.1+esm1", "binary_name": "libswscale2-dbgsym" } ] }