Bug 33430 - ffmpeg new security issue CVE-2023-49528
Summary: ffmpeg new security issue CVE-2023-49528
Status: NEW
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: Cauldron
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: Nicolas Salguero
QA Contact: Sec team
URL:
Whiteboard: MGA9TOO
Keywords:
Depends on:
Blocks:
 
Reported: 2024-07-25 09:04 CEST by Nicolas Salguero
Modified: 2024-07-25 21:22 CEST (History)
1 user (show)

See Also:
Source RPM: ffmpeg-5.1.5-3.mga10.src.rpm
CVE: CVE-2023-49528
Status comment:


Attachments

Description Nicolas Salguero 2024-07-25 09:04:46 CEST
Fedora has issued an advisory on July 21:
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/R3BMDGSJN6WOKM5DG6WR4ITFVPI77UHH/

Currently, the fix is not available in versions 5.1.x.

Mageia 9 is also affected.
Nicolas Salguero 2024-07-25 09:05:37 CEST

Source RPM: (none) => ffmpeg-5.1.5-3.mga10.src.rpm
CVE: (none) => CVE-2023-49528
Whiteboard: (none) => MGA9TOO

Comment 1 Lewis Smith 2024-07-25 21:22:08 CEST
No fix available yet, but someone needs to hold this until one shows up.
Assigning to NicolasS who is best placed to spot the fix when it appears; either to update the version, or pass it on.

CC: (none) => geiger.david68210
Assignee: bugsquad => nicolas.salguero


Note You need to log in before you can comment on or make changes to this bug.