CVE-2015-6761

Publication date 15 October 2015

Last updated 24 July 2024


Ubuntu priority

The update_dimensions function in libavcodec/vp8.c in FFmpeg through 2.8.1, as used in Google Chrome before 46.0.2490.71 and other products, relies on a coefficient-partition count during multi-threaded operation, which allows remote attackers to cause a denial of service (race condition and memory corruption) or possibly have unspecified other impact via a crafted WebM file.

Read the notes from the security team

Status

Package Ubuntu Release Status
chromium-browser 18.04 LTS bionic
Fixed 47.0.2526.73-0ubuntu1.1218
17.10 artful
Fixed 47.0.2526.73-0ubuntu1.1218
17.04 zesty
Fixed 47.0.2526.73-0ubuntu1.1218
16.10 yakkety
Fixed 47.0.2526.73-0ubuntu1.1218
16.04 LTS xenial
Fixed 47.0.2526.73-0ubuntu1.1218
15.10 wily
Fixed 47.0.2526.73-0ubuntu0.15.10.1.1215
15.04 vivid
Fixed 47.0.2526.73-0ubuntu0.15.04.1.1190
14.04 LTS trusty
Fixed 47.0.2526.73-0ubuntu0.14.04.1.1106
12.04 LTS precise Ignored
ffmpeg 18.04 LTS bionic
Not affected
17.10 artful
Not affected
17.04 zesty
Not affected
16.10 yakkety
Not affected
16.04 LTS xenial
Not affected
15.10 wily
Fixed 7:2.7.4-0ubuntu0.15.10.1
15.04 vivid
Fixed 7:2.5.9-0ubuntu0.15.04.1
14.04 LTS trusty Not in release
12.04 LTS precise Not in release
libav 18.04 LTS bionic Not in release
17.10 artful Not in release
17.04 zesty Not in release
16.10 yakkety Not in release
16.04 LTS xenial Not in release
15.10 wily Not in release
15.04 vivid Ignored end of life
14.04 LTS trusty Ignored
12.04 LTS precise
Not affected
oxide-qt 18.04 LTS bionic Not in release
17.10 artful
Fixed 1.10.3-0ubuntu0.15.10.1
17.04 zesty
Fixed 1.10.3-0ubuntu0.15.10.1
16.10 yakkety
Fixed 1.10.3-0ubuntu0.15.10.1
16.04 LTS xenial
Fixed 1.10.3-0ubuntu0.15.10.1
15.10 wily
Fixed 1.10.3-0ubuntu0.15.10.1
15.04 vivid
Fixed 1.10.3-0ubuntu0.15.04.1
14.04 LTS trusty
Fixed 1.10.3-0ubuntu0.14.04.1
12.04 LTS precise Not in release

Notes


ebarretto

as of 2018-09-27, no equivalent fix in libav.

Patch details

For informational purposes only. We recommend not to cherry-pick updates. How can I get the fixes?

Package Patch details
ffmpeg