Assertion failure in FFmpeg - CVE-2018-15822
Published: August 24, 2018 / Updated: August 27, 2018
Vulnerability details
The vulnerability allows a local attacker to cause DoS condition on the target system.
The vulnerability exists due to insufficient checks for an empty audio packet by the flv_write_packet function, as defined in the libavformat/flvenc.c source code file. A local attacker can access the system and execute a specially crafted application that submits malicious input to trigger an assertion failure and cause the service to crash.
Affected software
SUSE Package Hub for SUSE Linux Enterprise
ffmpeg (Alpine package)
ffmpeg (Ubuntu package)
libswscale-ffmpeg3 (Ubuntu package)
libavcodec-ffmpeg-extra56 (Ubuntu package)
libavcodec-ffmpeg56 (Ubuntu package)
libavdevice-ffmpeg56 (Ubuntu package)
libavfilter-ffmpeg5 (Ubuntu package)
libavformat-ffmpeg56 (Ubuntu package)
libavresample-ffmpeg2 (Ubuntu package)
libavutil-ffmpeg54 (Ubuntu package)
libpostproc-ffmpeg53 (Ubuntu package)
libswresample-ffmpeg1 (Ubuntu package)
libavcodec57 (Ubuntu package)
libswscale4 (Ubuntu package)
libswresample2 (Ubuntu package)
libpostproc54 (Ubuntu package)
libavutil55 (Ubuntu package)
libavresample3 (Ubuntu package)
libavformat57 (Ubuntu package)
libavfilter6 (Ubuntu package)
libavfilter-extra6 (Ubuntu package)
libavdevice57 (Ubuntu package)
libavcodec-extra57 (Ubuntu package)
libavutil56 (Ubuntu package)
libavresample4 (Ubuntu package)
libavformat58 (Ubuntu package)
libavfilter7 (Ubuntu package)
libavfilter-extra7 (Ubuntu package)
libavdevice58 (Ubuntu package)
libavcodec58 (Ubuntu package)
libavcodec-extra58 (Ubuntu package)
libpostproc55 (Ubuntu package)
libswresample3 (Ubuntu package)
libswscale5 (Ubuntu package)
SUSE Linux
Opensuse
Ubuntu
How to mitigate CVE-2018-15822
ffmpeg (Ubuntu package) - addressed in versions 7:2.8.17-0ubuntu0.1, 7:3.4.6-0ubuntu0.18.04.1, 7:3.4.8-0ubuntu0.2, 7:4.0.4-0ubuntu1, 7:4.1.3-0ubuntu1, 7:4.2.4-1ubuntu0.1
libswscale-ffmpeg3 (Ubuntu package) - update to 7:2.8.17-0ubuntu0.1
libavcodec-ffmpeg-extra56 (Ubuntu package) - update to 7:2.8.17-0ubuntu0.1
libavcodec-ffmpeg56 (Ubuntu package) - update to 7:2.8.17-0ubuntu0.1
libavdevice-ffmpeg56 (Ubuntu package) - update to 7:2.8.17-0ubuntu0.1
libavfilter-ffmpeg5 (Ubuntu package) - update to 7:2.8.17-0ubuntu0.1
libavformat-ffmpeg56 (Ubuntu package) - update to 7:2.8.17-0ubuntu0.1
libavresample-ffmpeg2 (Ubuntu package) - update to 7:2.8.17-0ubuntu0.1
libavutil-ffmpeg54 (Ubuntu package) - update to 7:2.8.17-0ubuntu0.1
libpostproc-ffmpeg53 (Ubuntu package) - update to 7:2.8.17-0ubuntu0.1
libswresample-ffmpeg1 (Ubuntu package) - update to 7:2.8.17-0ubuntu0.1
libavcodec57 (Ubuntu package) - update to 7:3.4.8-0ubuntu0.2
libswscale4 (Ubuntu package) - update to 7:3.4.8-0ubuntu0.2
libswresample2 (Ubuntu package) - update to 7:3.4.8-0ubuntu0.2
libpostproc54 (Ubuntu package) - update to 7:3.4.8-0ubuntu0.2
libavutil55 (Ubuntu package) - update to 7:3.4.8-0ubuntu0.2
libavresample3 (Ubuntu package) - update to 7:3.4.8-0ubuntu0.2
libavformat57 (Ubuntu package) - update to 7:3.4.8-0ubuntu0.2
libavfilter6 (Ubuntu package) - update to 7:3.4.8-0ubuntu0.2
libavfilter-extra6 (Ubuntu package) - update to 7:3.4.8-0ubuntu0.2
libavdevice57 (Ubuntu package) - update to 7:3.4.8-0ubuntu0.2
libavcodec-extra57 (Ubuntu package) - update to 7:3.4.8-0ubuntu0.2
libavutil56 (Ubuntu package) - update to 7:4.2.4-1ubuntu0.1
libavresample4 (Ubuntu package) - update to 7:4.2.4-1ubuntu0.1
libavformat58 (Ubuntu package) - update to 7:4.2.4-1ubuntu0.1
libavfilter7 (Ubuntu package) - update to 7:4.2.4-1ubuntu0.1
libavfilter-extra7 (Ubuntu package) - update to 7:4.2.4-1ubuntu0.1
libavdevice58 (Ubuntu package) - update to 7:4.2.4-1ubuntu0.1
libavcodec58 (Ubuntu package) - update to 7:4.2.4-1ubuntu0.1
libavcodec-extra58 (Ubuntu package) - update to 7:4.2.4-1ubuntu0.1
libpostproc55 (Ubuntu package) - update to 7:4.2.4-1ubuntu0.1
libswresample3 (Ubuntu package) - update to 7:4.2.4-1ubuntu0.1
libswscale5 (Ubuntu package) - update to 7:4.2.4-1ubuntu0.1