Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

Zero-Day FFmpeg Vulnerability Lets Anyone Steal Files from Remote Machines
Softpedia ^ | Jan 13, 2016 22:03 GMT | Marius Nestor

Posted on 01/14/2016 7:18:26 PM PST by Utilizer

A zero-day vulnerability in the FFmpeg open-source multimedia framework, which is currently used in numerous Linux kernel-based operating systems and software applications, also for the Mac OS X and Windows platforms, was unveiled recently.

The vulnerability was discovered on January 12, 2016, by Russian programmer Maxim Andreev in the current stable builds of the FFmpeg software, and it would appear that it allows anyone who has the necessary skills to hack a computer to read local files on a remote machine and send them over the network using a specially crafted video file.

The vulnerability is limited to reading local files and sending them over the network, not to remote code execution, but it's enough to do some damage. The FFmpeg developers are aware of the issue, and they are trying to patch it as we speak. James Darnley of FFmpeg suggests that disabling HLS (HTTP Live Streaming) while building the package should do the trick until a fix is committed.

(Excerpt) Read more at news.softpedia.com ...


TOPICS: Computers/Internet
KEYWORDS: filethreat; freebsd; linux; macos; mpeg; security; tickletickletickle; unix; vulnerability; windows; windowspinglist
FFmpeg vulnerability affecting several OSs', already patched in Arch Linux.

Linux coders and security pros are the best!

1 posted on 01/14/2016 7:18:26 PM PST by Utilizer
[ Post Reply | Private Reply | View Replies]

To: Utilizer

Already patched in SUSE.


2 posted on 01/14/2016 7:19:25 PM PST by steve86 (Prophecies of Maelmhaedhoc O�Morgair (Latin form: Malachy))
[ Post Reply | Private Reply | To 1 | View Replies]

To: Utilizer

Thanks for posting...


3 posted on 01/14/2016 7:21:04 PM PST by Ghost of SVR4 (So many are so hopelessly dependent on the government that they will fight to protect it.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: steve86

Great news! Thanks. :)


4 posted on 01/14/2016 7:21:24 PM PST by Utilizer (Bacon A'kbar! - In world today are only peaceful people, and the muzrims trying to kill them)
[ Post Reply | Private Reply | To 2 | View Replies]

To: Ghost of SVR4

No worries. :)


5 posted on 01/14/2016 7:22:43 PM PST by Utilizer (Bacon A'kbar! - In world today are only peaceful people, and the muzrims trying to kill them)
[ Post Reply | Private Reply | To 3 | View Replies]

To: All

Note that this affects ‘nix, ‘doze, and mac machines, according to the article.


6 posted on 01/14/2016 7:24:38 PM PST by Utilizer (Bacon A'kbar! - In world today are only peaceful people, and the muzrims trying to kill them)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Utilizer

“....a specially crafted video file.”

Disguised as free porn, no doubt. They won’t have any trouble getting guys to download it.


7 posted on 01/14/2016 7:46:54 PM PST by proxy_user
[ Post Reply | Private Reply | To 1 | View Replies]

To: Swordmaker

FYI ping...


8 posted on 01/14/2016 7:48:00 PM PST by TXnMA ("Allah: Satan's current alias. "Obama": Allah's current ally...)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Utilizer; dayglored; ShadowAce; ThunderSleeps
If you are not using FFmpeg, you shouldn't be vulnerable to this exploit, because you wouldn't have the codexes needed to decode the files.

"FFmpeg is a free software project that produces libraries and programs for handling multimedia data. FFmpeg includes libavcodec, an audio/video codec library used by several other projects, libavformat, an audio/video container mux and demux library, and the ffmpeg command line program for transcoding multimedia files. FFmpeg is published under the GNU Lesser General Public License 2.1+ or GNU General Public License 2+ (depending on which options are enabled).[6]

FFmpeg is developed under Linux, but it can be compiled under most operating systems, including Mac OS X, Microsoft Windows, as well as AmigaOS and its heir MorphOS. Most computing platforms and microprocessor instruction set architectures are also supported, like x86 (IA-32 and x86-64), PPC (PowerPC), ARM, DEC Alpha, SPARC, and MIPS.[7]

Most Mac users are already well covered with players that handle any multimedia files they may run into so are unlikely to download another multimedia file handling system.

After reading the information on it, I don't believe I am going to even ping the Apple Ping list for this one. . . it's a pretty geeky thing. It requires an active decision to install a player or codex that utilizes this file format.

9 posted on 01/14/2016 7:58:12 PM PST by Swordmaker (This tag line is a Microsoft insult free zone... but if the insults to Mac users continue....)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Utilizer
Note that this affects ‘nix, ‘doze, and mac machines, according to the article.

I think you missed something. From the first paragraph of the article:

"A zero-day vulnerability in the FFmpeg open-source multimedia framework, which is currently used in numerous Linux kernel-based operating systems and software applications, also for the Mac OS X and Windows platforms, was unveiled recently."

10 posted on 01/14/2016 8:01:49 PM PST by Swordmaker (This tag line is a Microsoft insult free zone... but if the insults to Mac users continue....)
[ Post Reply | Private Reply | To 6 | View Replies]

To: Swordmaker

Ah... “’doze” is coder-speak in certain circles for “Windows”, and I usually define it as such.

Cheers.


11 posted on 01/14/2016 8:04:51 PM PST by Utilizer (Bacon A'kbar! - In world today are only peaceful people, and the muzrims trying to kill them)
[ Post Reply | Private Reply | To 10 | View Replies]

To: Swordmaker; Utilizer

Doze == Windows. I’ll ping it in the morning when I’m at my regular box.


12 posted on 01/14/2016 8:07:02 PM PST by dayglored ("Listen. Strange women lying in ponds distributing swords is no basis for a system of government.")
[ Post Reply | Private Reply | To 10 | View Replies]

To: Utilizer; dayglored
Sorry fellows, I have had a long day at work, and am pooped. Slipped right by me. I had left a new Mac doing a migration over night and a power failure in the storms exceeded the Uninterruptible Power Supply it was connected to, so re-migrating this morning had some REALLY interesting consequences I've never seen before. Apparently the interruption occurred at a VERY bad time. It resulted after the second migration with TWO copies of each user folder, but only one capable of being logged into, however files readable from both, but opening a file in the login user folder, were saved to the non-login user folder, and vice-verse. It played havoc with things like our bookkeeping software. It seemed to switch off every other time as to which one would be opened from the short-cut alias on the desktop of the bookkeeping software, so entries done the previous time opened would be missing on the next opening, but back on the second opening! It took some real noodling to figure out what kind of BLACK MAGIC was going on that would cause that . . . and why the email was totally screwed up in each user's folder.

Add to that that the second identical user folder from the failed, interrupted migration was INVISIBLE due to never completing the migration, but only visible via the Terminal. . . Fun. Apparently the file pointers were totally screwed up. . .

The solution was to delete both duplicate user folders AFTER I found the amazing invisible files, and re-migrate the users. . . but figuring out WHY there was a problem caused me to lose some hair which I prefer to keep on my head. Once that was done, everything was copacetic again.

I gotta say that the Fusion Drive on this new iMac is FAST! The Mac Boots from a cold state in about three seconds and opens a user in about two.

13 posted on 01/14/2016 8:48:39 PM PST by Swordmaker (This tag line is a Microsoft insult free zone... but if the insults to Mac users continue....)
[ Post Reply | Private Reply | To 11 | View Replies]

To: dayglored

Right, then. Take care. :)


14 posted on 01/14/2016 9:56:23 PM PST by Utilizer (Bacon A'kbar! - In world today are only peaceful people, and the muzrims trying to kill them)
[ Post Reply | Private Reply | To 12 | View Replies]

To: Swordmaker

Sounds like an interesting day. Relax, and feel free to return to this thread when the thought next arrives. Might have more info and fixes in by tomorrow then.


15 posted on 01/14/2016 9:58:44 PM PST by Utilizer (Bacon A'kbar! - In world today are only peaceful people, and the muzrims trying to kill them)
[ Post Reply | Private Reply | To 13 | View Replies]

To: proxy_user

Already happening...


16 posted on 01/14/2016 10:52:57 PM PST by Utilizer (Bacon A'kbar! - In world today are only peaceful people, and the muzrims trying to kill them)
[ Post Reply | Private Reply | To 7 | View Replies]

To: Utilizer
11-16-2015: "Firefox 43 to Use FFmpeg by Default on Linux":

http://news.softpedia.com/news/firefox-43-to-use-ffmpeg-by-default-on-linux-496213.shtml

17 posted on 01/14/2016 11:28:16 PM PST by TChad
[ Post Reply | Private Reply | To 1 | View Replies]

To: rdb3; Calvinist_Dark_Lord; JosephW; Only1choice____Freedom; amigatec; Ernest_at_the_Beach; ...

18 posted on 01/14/2016 11:50:13 PM PST by ShadowAce (Linux - The Ultimate Windows Service Pack)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Swordmaker; Utilizer; Abby4116; afraidfortherepublic; aft_lizard; AF_Blue; amigatec; AppyPappy; ...
Using the FFmpeg video decoder? Check this out ... PING!

You can find all the Windows Ping list threads with FR search: just search on keyword "windowspinglist".

Thanks to Swordmaker and Utilizer for the ping!!

19 posted on 01/15/2016 5:43:27 AM PST by dayglored ("Listen. Strange women lying in ponds distributing swords is no basis for a system of government.")
[ Post Reply | Private Reply | To 12 | View Replies]

To: dayglored

Thanks


20 posted on 01/15/2016 8:46:40 AM PST by GOPJ (Trump's living rent-free in Jeb's head - Trump's wearing a robe and comfy slippers. FlickLives)
[ Post Reply | Private Reply | To 19 | View Replies]

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson