summaryrefslogtreecommitdiffstats
path: root/scripts/tiny/ksize.py
diff options
context:
space:
mode:
authorNarpat Mali <narpat.mali@windriver.com>2022-11-23 14:20:22 +0000
committerRichard Purdie <richard.purdie@linuxfoundation.org>2022-11-27 23:54:50 +0000
commit2a642aa2b1b96bd84e650a7c3ebade4d2d7c3863 (patch)
tree2746cca8360114c8459da6da70cde7e641169a5e /scripts/tiny/ksize.py
parent80dc1462079ced1e34d039a7c4c8a9cf0e40e9e7 (diff)
downloadpoky-2a642aa2b1b96bd84e650a7c3ebade4d2d7c3863.tar.gz
ffmpeg: fix for CVE-2022-3964
A vulnerability classified as problematic has been found in ffmpeg. This affects an unknown part of the file libavcodec/rpzaenc.c of the component QuickTime RPZA Video Encoder. The manipulation of the argument y_size leads to out-of-bounds read. It is possible to initiate the attack remotely. The name of the patch is 92f9b28ed84a77138105475beba16c146bdaf984. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-213543. Reference: https://nvd.nist.gov/vuln/detail/CVE-2022-3964 Upstream Fix: https://github.com/FFmpeg/FFmpeg/commit/92f9b28ed84a77138105475beba16c146bdaf984 (From OE-Core rev: 4595f85e7ce867d68ca9d6a6e3ad2544565be3cc) Signed-off-by: Narpat Mali <narpat.mali@windriver.com> Signed-off-by: Alexandre Belloni <alexandre.belloni@bootlin.com> Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
Diffstat (limited to 'scripts/tiny/ksize.py')
0 files changed, 0 insertions, 0 deletions