First published: Tue Apr 19 2022(Updated: )
An integer overflow vulnerability was found in FFmpeg versions before 4.4.2 and before 5.0.1 in g729_parse() in llibavcodec/g729_parser.c when processing a specially crafted file.
Credit: patrick@puiterwijk.org patrick@puiterwijk.org patrick@puiterwijk.org
Affected Software | Affected Version | How to fix |
---|---|---|
ubuntu/ffmpeg | <7:4.4.2-0ubuntu0.21.10.1 | 7:4.4.2-0ubuntu0.21.10.1 |
ubuntu/ffmpeg | <7:4.4.2-0ubuntu0.22.04.1 | 7:4.4.2-0ubuntu0.22.04.1 |
ubuntu/ffmpeg | <7:4.4.2-1 | 7:4.4.2-1 |
FFmpeg FFmpeg | >=4.2<4.4.2 | |
FFmpeg FFmpeg | =5.0 | |
debian/ffmpeg | 7:4.3.6-0+deb11u1 7:4.3.7-0+deb11u1 7:5.1.5-0+deb12u1 7:6.1.1-5 7:7.0.1-5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-1475 is an integer overflow vulnerability found in FFmpeg versions before 4.4.2 and before 5.0.1 in g729_parse() in llibavcodec/g729_parser.c when processing a specially crafted file.
FFmpeg versions before 4.4.2 and before 5.0.1 are affected by CVE-2022-1475.
CVE-2022-1475 has a severity level of low.
To fix CVE-2022-1475 on Ubuntu, update the ffmpeg package to version 7:4.4.2-1, 7:4.4.2-0ubuntu0.21.10.1, or 7:4.4.2-0ubuntu0.22.04.1 depending on your Ubuntu version.
To fix CVE-2022-1475 on Debian, update the ffmpeg package to version 7:4.1.9-0+deb10u1, 7:4.1.11-0+deb10u1, 7:4.3.6-0+deb11u1, 7:5.1.3-1, or 7:6.0-7 depending on your Debian version.