Wind River Support Network

HomeDefectsLIN1022-2702
Fixed

LIN1022-2702 : Security Advisory - ffmpeg - CVE-2022-3109

Created: Dec 16, 2022    Updated: Feb 13, 2023
Resolved Date: Feb 13, 2023
Found In Version: 10.22.33.1
Severity: Standard
Applicable for: Wind River Linux LTS 22
Component/s: Userspace

Description

An issue was discovered in the FFmpeg through 3.0. vp3_decode_frame in libavcodec/vp3.c lacks check of the return value of av_malloc() and will cause the null pointer dereference, impacting confidentiality and availability.

CREATE(Triage):(User=admin) CVE-2022-3109 (https://nvd.nist.gov/vuln/detail/CVE-2022-3109)

CVEs


Live chat
Online