
DescriptionA vulnerability classified as problematic was found in FFmpeg 2.0. Affected by this vulnerability is an unknown functionality of the component HEVC Video Decoder. The manipulation leads to memory corruption. The attack can be launched remotely. It is recommended to apply a patch to fix this issue.
SourceCVE

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
ffmpeg (PTS)stretch (security)7:3.2.18-0+deb9u1fixed
stretch (lts), stretch7:3.2.19-0+deb9u4fixed
buster (security), buster, buster (lts)7:4.1.11-0+deb10u1fixed
bullseye (security)7:4.3.8-0+deb11u1fixed
bookworm (security), bookworm7:5.1.6-0+deb12u1fixed
trixie, sid7:7.0.2-3fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
ffmpegsource(unstable)(not affected)


- ffmpeg <not-affected> (Fixed before re-introduction to Debian as src:ffmpeg)
Fixed by:;a=commit;h=d1e6602665d5ec1b7e211ab27b298c26139f82cc (n2.2-rc1)

