Wind River Support Network

HomeDefectsLIN5-20606
Fixed

LIN5-20606 : Security Advisory - gst-ffmpeg & libav - CVE-2015-3395

Created: Jun 30, 2015    Updated: Dec 19, 2017
Resolved Date: Aug 19, 2015
Found In Version: 5.0.1.27
Fix Version: 5.0.1.30
Severity: Standard
Applicable for: Wind River Linux 5
Component/s: Userspace

Description

The msrle_decode_pal4 function in msrledec.c in Libav before 10.7 and 11.x before 11.4 and FFmpeg before 2.0.7, 2.2.x before 2.2.15, 2.4.x before 2.4.8, 2.5.x before 2.5.6, and 2.6.x before 2.6.2 allows remote attackers to have unspecified impact via a crafted image, related to a pixel pointer, which triggers an out-of-bounds array access.

http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2015-3395

Other Downloads


Live chat
Online