Debian Security Advisory

DLA-515-1 libav -- LTS security update

Date Reported:
14 Jun 2016
Affected Packages:
libav
Vulnerable:
Yes
Security database references:
In Mitre's CVE dictionary: CVE-2016-3062.
More information:

It was discovered that there was a memory corruption issue in libav (a multimedia player, server, encoder and transcoder) when parsing .mp4 files which could lead to crash or possibly execute arbitrary code.

For Debian 7 Wheezy, this issue has been fixed in libav version 6:0.8.17-2+deb7u2.

We recommend that you upgrade your libav packages.