New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 814456 link

Starred by 2 users

Issue metadata

Status: Assigned
Owner:
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Chrome
Pri: 2
Type: Bug



Sign in to add a comment

Security: Libavcodec in FFmpeg before 0.11 allows remote attackers to execute arbitrary code

Reported by nathanb@lenovo-chrome.com, Feb 21 2018

Issue description

CVE-2012-5359 and CVE-2012-5360

These CVE reports describe vulnerabilities in libavcodec allowing remote attackers to execute arbitrary code via crafted ASF and QT files, respectively. 

I note that the version of ffmpeg included in Chrome OS is 0.10.3, and (unless I overlooked something) I don't see any patches for this particular issue.
 
Components: Internals>Media>FFmpeg
Labels: OS-Chrome
Status: WontFix (was: Unconfirmed)
Note that the copy in the Chrome OS tree is only used for testing purposes and is not shipped in the production image. Chrome does contain a copy of ffmpeg, but that is recent version: https://cs.chromium.org/chromium/src/third_party/ffmpeg/RELEASE

Thus, Chrome OS is not vulnerable to this.
Cc: hungte@chromium.org
Hung-Te, the dependency graph suggests we carry the ffmpeg ebuild for factory. Any chance we can uprev to a more modern version?

Comment 4 by hungte@chromium.org, Feb 23 2018

Cc: stimim@chromium.org
+stimim

I think we have no concern upgrading ffmpeg.

Comment 5 by hungte@chromium.org, Feb 23 2018

Cc: chromeos-factory-eng@google.com
Owner: chenghan@chromium.org
Status: Assigned (was: WontFix)
Temporarily assign to chenghan@.

Cheng-han, can you try upgrade the package?
Components: -Internals>Media>FFmpeg
Labels: -Type-Bug-Security -Restrict-View-SecurityTeam Type-Bug
Converting to regular bug - no security impact per comment #2.
Triage nag: This Chrome OS bug has an owner but no component. Please add a component so that this can be tracked by the relevant team.
<UI triage> Bug owners, please add the appropriate component to your bug. Thanks!
Components: Factory
Labels: Pri-2
Setting defect without priority to Pri-2.
Setting defect without priority to Pri-2.

Sign in to add a comment