<?xml version="1.0" encoding="utf-8"?>
  <?xml-stylesheet type="text/xsl" href="sa-render.xsl"?>
  <update from="huaweicloud.com" type="security" status="stable" version="1">
    <id>HCE2-SA-2024-0314</id>
    <title>An update for ffmpeg is now available for HCE 2.0</title>
    <severity>Critical</severity>
    <release>HCE 2.0</release>
    <issued date="2024-12-20 09:52:44"/>
    <updated date="2024-12-20 09:52:44"/>
    <references>
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2024-36616" id="CVE-2024-36616" title="CVE-2024-36616 Base Score: 6.5 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" type="cve"/>
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2024-35368" id="CVE-2024-35368" title="CVE-2024-35368 Base Score: 9.8 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" type="cve"/>
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2024-35366" id="CVE-2024-35366" title="CVE-2024-35366 Base Score: 9.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H" type="cve"/>
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2024-35367" id="CVE-2024-35367" title="CVE-2024-35367 Base Score: 9.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H" type="cve"/>
    </references>
    <description>Security Fix(es):

An integer overflow in the component /libavformat/westwood_vqa.c of FFmpeg n6.1.1 allows attackers to cause a denial of service in the application via a crafted VQA file. (CVE-2024-36616)

FFmpeg n7.0 is affected by a Double Free via the rkmpp_retrieve_frame function within libavcodec/rkmppdec.c. (CVE-2024-35368)

FFmpeg n6.1.1 is Integer Overflow. The vulnerability exists in the parse_options function of sbgdec.c within the libavformat module. When parsing certain options, the software does not adequately validate the input. This allows for negative duration values to be accepted without proper bounds checking. (CVE-2024-35366)

FFmpeg n6.1.1 has an Out-of-bounds Read via libavcodec/ppc/vp8dsp_altivec.c, static const vec_s8 h_subpel_filters_outer (CVE-2024-35367)
</description>
    <pkglist>
      <collection short="HCE 2.0" package="ffmpeg">
        <name>HCE 2.0</name>
        <package arch="aarch64" name="ffmpeg-devel" version="4.2.4" release="4.r16.hce2">
          <filename>ffmpeg-devel-4.2.4-4.r16.hce2.aarch64.rpm</filename>
        </package>
        <package arch="aarch64" name="ffmpeg-libs" version="4.2.4" release="4.r16.hce2">
          <filename>ffmpeg-libs-4.2.4-4.r16.hce2.aarch64.rpm</filename>
        </package>
        <package arch="aarch64" name="libavdevice" version="4.2.4" release="4.r16.hce2">
          <filename>libavdevice-4.2.4-4.r16.hce2.aarch64.rpm</filename>
        </package>
        <package arch="x86_64" name="ffmpeg-devel" version="4.2.4" release="4.r16.hce2">
          <filename>ffmpeg-devel-4.2.4-4.r16.hce2.x86_64.rpm</filename>
        </package>
        <package arch="x86_64" name="ffmpeg-libs" version="4.2.4" release="4.r16.hce2">
          <filename>ffmpeg-libs-4.2.4-4.r16.hce2.x86_64.rpm</filename>
        </package>
        <package arch="x86_64" name="libavdevice" version="4.2.4" release="4.r16.hce2">
          <filename>libavdevice-4.2.4-4.r16.hce2.x86_64.rpm</filename>
        </package>
      </collection>
    </pkglist>
  </update>
