Wind River Support Network

HomeDefectsLIN1021-4948
Fixed

LIN1021-4948 : Security Advisory - ffmpeg - CVE-2022-3109

Created: Dec 16, 2022    Updated: Dec 26, 2022
Resolved Date: Dec 26, 2022
Found In Version: 10.21.20.1
Severity: Standard
Applicable for: Wind River Linux LTS 21
Component/s: Userspace

Description

An issue was discovered in the FFmpeg through 3.0. vp3_decode_frame in libavcodec/vp3.c lacks check of the return value of av_malloc() and will cause the null pointer dereference, impacting confidentiality and availability.

CREATE(Triage):(User=admin) CVE-2022-3109 (https://nvd.nist.gov/vuln/detail/CVE-2022-3109)

CVEs


Live chat
Online