UBUNTU-CVE-2018-13300

Source
https://ubuntu.com/security/CVE-2018-13300
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2018/UBUNTU-CVE-2018-13300.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2018-13300
Related
Published
2018-07-05T17:29:00Z
Modified
2024-11-20T12:20:25Z
Severity
  • 8.1 (High) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H CVSS Calculator
Summary
[none]
Details

In FFmpeg 3.2 and 4.0.1, an improper argument (AVCodecParameters) passed to the avprivrequestsample function in the handle_eac3 function in libavformat/movenc.c may trigger an out-of-array read while converting a crafted AVI file to MPEG4, leading to a denial of service and possibly an information disclosure.

References

Affected packages

Ubuntu:Pro:16.04:LTS / oxide-qt

Package

Name
oxide-qt
Purl
pkg:deb/ubuntu/oxide-qt?arch=src?distro=esm-infra/xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*

1.9.5-0ubuntu1
1.10.3-0ubuntu0.15.10.1
1.10.3-0ubuntu0.15.10.2
1.11.3-0ubuntu3
1.11.4-0ubuntu1
1.11.5-0ubuntu1
1.12.5-0ubuntu1
1.12.6-0ubuntu1
1.12.7-0ubuntu1
1.13.6-0ubuntu1
1.14.7-0ubuntu1
1.14.9-0ubuntu0.16.04.1
1.15.7-0ubuntu0.16.04.1
1.15.8-0ubuntu0.16.04.1
1.16.5-0ubuntu0.16.04.1
1.17.7-0ubuntu0.16.04.1
1.17.9-0ubuntu0.16.04.1
1.18.3-0ubuntu0.16.04.1
1.18.5-0ubuntu0.16.04.1
1.19.4-0ubuntu0.16.04.1
1.20.4-0ubuntu0.16.04.1
1.21.5-0ubuntu0.16.04.1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:Pro:16.04:LTS / gst-libav1.0

Package

Name
gst-libav1.0
Purl
pkg:deb/ubuntu/gst-libav1.0?arch=src?distro=esm-apps/xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*

1.6.0-1
1.6.0-2
1.6.1-1
1.6.2-1
1.7.1-1
1.7.2-1
1.7.90-1
1.8.0-1
1.8.1-1~ubuntu1
1.8.2-1~ubuntu1
1.8.3-1ubuntu0.1
1.8.3-1ubuntu0.2

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:Pro:16.04:LTS / kino

Package

Name
kino
Purl
pkg:deb/ubuntu/kino?arch=src?distro=esm-apps/xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*

1.3.4-2.1build2

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:Pro:16.04:LTS / mythtv

Package

Name
mythtv
Purl
pkg:deb/ubuntu/mythtv?arch=src?distro=esm-apps/xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2:0.*

2:0.27.1+fixes.20140624.aa822f5-0ubuntu6
2:0.27.1+fixes.20140624.aa822f5-0ubuntu7
2:0.27.1+fixes.20140624.aa822f5-0ubuntu9
2:0.28.0+fixes.20160217.44fd8a6-0ubuntu4
2:0.28.0+fixes.20160229.ae35a28-0ubuntu1
2:0.28.0+fixes.20160321.39e409d-0ubuntu1
2:0.28.0+fixes.20160321.39e409d-0ubuntu2
2:0.28.0+fixes.20160325.2520617-0ubuntu3
2:0.28.0+fixes.20160413.15cf421-0ubuntu1
2:0.28.0+fixes.20160413.15cf421-0ubuntu2
2:0.28.0+fixes.20160413.15cf421-0ubuntu2.16.04.1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:Pro:16.04:LTS / vice

Package

Name
vice
Purl
pkg:deb/ubuntu/vice?arch=src?distro=esm-apps/xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2.*

2.4.dfsg+2.4.20-1
2.4.dfsg+2.4.25-1ubuntu1
2.4.dfsg+2.4.25-2

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:18.04:LTS / ffmpeg

Package

Name
ffmpeg
Purl
pkg:deb/ubuntu/ffmpeg?arch=src?distro=bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
7:3.4.4-0ubuntu0.18.04.1

Affected versions

7:3.*

7:3.3.4-2
7:3.3.4-2build3
7:3.4-2ubuntu2
7:3.4-4
7:3.4-4build1
7:3.4.1-1
7:3.4.1-1build1
7:3.4.2-1
7:3.4.2-1build1
7:3.4.2-2

Ecosystem specific

{
    "availability": "No subscription required",
    "ubuntu_priority": "medium",
    "binaries": [
        {
            "binary_version": "7:3.4.4-0ubuntu0.18.04.1",
            "binary_name": "ffmpeg"
        },
        {
            "binary_version": "7:3.4.4-0ubuntu0.18.04.1",
            "binary_name": "ffmpeg-dbgsym"
        },
        {
            "binary_version": "7:3.4.4-0ubuntu0.18.04.1",
            "binary_name": "ffmpeg-doc"
        },
        {
            "binary_version": "7:3.4.4-0ubuntu0.18.04.1",
            "binary_name": "libavcodec-dev"
        },
        {
            "binary_version": "7:3.4.4-0ubuntu0.18.04.1",
            "binary_name": "libavcodec-extra"
        },
        {
            "binary_version": "7:3.4.4-0ubuntu0.18.04.1",
            "binary_name": "libavcodec-extra57"
        },
        {
            "binary_version": "7:3.4.4-0ubuntu0.18.04.1",
            "binary_name": "libavcodec-extra57-dbgsym"
        },
        {
            "binary_version": "7:3.4.4-0ubuntu0.18.04.1",
            "binary_name": "libavcodec57"
        },
        {
            "binary_version": "7:3.4.4-0ubuntu0.18.04.1",
            "binary_name": "libavcodec57-dbgsym"
        },
        {
            "binary_version": "7:3.4.4-0ubuntu0.18.04.1",
            "binary_name": "libavdevice-dev"
        },
        {
            "binary_version": "7:3.4.4-0ubuntu0.18.04.1",
            "binary_name": "libavdevice57"
        },
        {
            "binary_version": "7:3.4.4-0ubuntu0.18.04.1",
            "binary_name": "libavdevice57-dbgsym"
        },
        {
            "binary_version": "7:3.4.4-0ubuntu0.18.04.1",
            "binary_name": "libavfilter-dev"
        },
        {
            "binary_version": "7:3.4.4-0ubuntu0.18.04.1",
            "binary_name": "libavfilter-extra"
        },
        {
            "binary_version": "7:3.4.4-0ubuntu0.18.04.1",
            "binary_name": "libavfilter-extra6"
        },
        {
            "binary_version": "7:3.4.4-0ubuntu0.18.04.1",
            "binary_name": "libavfilter-extra6-dbgsym"
        },
        {
            "binary_version": "7:3.4.4-0ubuntu0.18.04.1",
            "binary_name": "libavfilter6"
        },
        {
            "binary_version": "7:3.4.4-0ubuntu0.18.04.1",
            "binary_name": "libavfilter6-dbgsym"
        },
        {
            "binary_version": "7:3.4.4-0ubuntu0.18.04.1",
            "binary_name": "libavformat-dev"
        },
        {
            "binary_version": "7:3.4.4-0ubuntu0.18.04.1",
            "binary_name": "libavformat57"
        },
        {
            "binary_version": "7:3.4.4-0ubuntu0.18.04.1",
            "binary_name": "libavformat57-dbgsym"
        },
        {
            "binary_version": "7:3.4.4-0ubuntu0.18.04.1",
            "binary_name": "libavresample-dev"
        },
        {
            "binary_version": "7:3.4.4-0ubuntu0.18.04.1",
            "binary_name": "libavresample3"
        },
        {
            "binary_version": "7:3.4.4-0ubuntu0.18.04.1",
            "binary_name": "libavresample3-dbgsym"
        },
        {
            "binary_version": "7:3.4.4-0ubuntu0.18.04.1",
            "binary_name": "libavutil-dev"
        },
        {
            "binary_version": "7:3.4.4-0ubuntu0.18.04.1",
            "binary_name": "libavutil55"
        },
        {
            "binary_version": "7:3.4.4-0ubuntu0.18.04.1",
            "binary_name": "libavutil55-dbgsym"
        },
        {
            "binary_version": "7:3.4.4-0ubuntu0.18.04.1",
            "binary_name": "libpostproc-dev"
        },
        {
            "binary_version": "7:3.4.4-0ubuntu0.18.04.1",
            "binary_name": "libpostproc54"
        },
        {
            "binary_version": "7:3.4.4-0ubuntu0.18.04.1",
            "binary_name": "libpostproc54-dbgsym"
        },
        {
            "binary_version": "7:3.4.4-0ubuntu0.18.04.1",
            "binary_name": "libswresample-dev"
        },
        {
            "binary_version": "7:3.4.4-0ubuntu0.18.04.1",
            "binary_name": "libswresample2"
        },
        {
            "binary_version": "7:3.4.4-0ubuntu0.18.04.1",
            "binary_name": "libswresample2-dbgsym"
        },
        {
            "binary_version": "7:3.4.4-0ubuntu0.18.04.1",
            "binary_name": "libswscale-dev"
        },
        {
            "binary_version": "7:3.4.4-0ubuntu0.18.04.1",
            "binary_name": "libswscale4"
        },
        {
            "binary_version": "7:3.4.4-0ubuntu0.18.04.1",
            "binary_name": "libswscale4-dbgsym"
        }
    ]
}

Ubuntu:Pro:18.04:LTS / gst-libav1.0

Package

Name
gst-libav1.0
Purl
pkg:deb/ubuntu/gst-libav1.0?arch=src?distro=esm-apps/bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*

1.12.2-1
1.12.3-1
1.12.4-1
1.13.91-1
1.14.0-1
1.14.1-1~ubuntu18.04.1
1.14.4-0ubuntu1~ubuntu18.04.1
1.14.5-0ubuntu1~18.04.1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:Pro:18.04:LTS / kino

Package

Name
kino
Purl
pkg:deb/ubuntu/kino?arch=src?distro=esm-apps/bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*

1.3.4-2.3
1.3.4-2.4

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:Pro:18.04:LTS / mythtv

Package

Name
mythtv
Purl
pkg:deb/ubuntu/mythtv?arch=src?distro=esm-apps/bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2:29.*

2:29.0+fixes.20170728.696806310a-0ubuntu1
2:29.0+fixes.20170728.696806310a-0ubuntu3
2:29.0+fixes.20170728.696806310a-0ubuntu4
2:29.0+fixes.20170728.696806310a-0ubuntu5
2:29.0+fixes.20170728.696806310a-0ubuntu6
2:29.0+fixes.20170728.696806310a-0ubuntu7
2:29.0+fixes.20170728.696806310a-0ubuntu8
2:29.1+fixes.20180220.9b7b962-0ubuntu2
2:29.1+fixes.20180220.9b7b962-0ubuntu3
2:29.1+fixes.20180414.329c235-0ubuntu3

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:Pro:18.04:LTS / vice

Package

Name
vice
Purl
pkg:deb/ubuntu/vice?arch=src?distro=esm-apps/bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

3.*

3.1.0.dfsg-1
3.1.0.dfsg1-1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:20.04:LTS / chromium-browser

Package

Name
chromium-browser
Purl
pkg:deb/ubuntu/chromium-browser?arch=src?distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

77.*

77.0.3865.120-0ubuntu1~snap1
77.0.3865.120-0ubuntu2

78.*

78.0.3904.70-0ubuntu1
78.0.3904.108-0ubuntu1

79.*

79.0.3945.79-0ubuntu1

80.*

80.0.3987.87-0ubuntu1
80.0.3987.162-0ubuntu1
80.0.3987.163-0ubuntu1

81.*

81.0.4044.129-0ubuntu0.20.04.1

83.*

83.0.4103.97-0ubuntu0.20.04.1

84.*

84.0.4147.105-0ubuntu0.20.04.1

1:85.*

1:85.0.4183.83-0ubuntu0.20.04.1
1:85.0.4183.83-0ubuntu0.20.04.2
1:85.0.4183.83-0ubuntu0.20.04.3

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:20.04:LTS / gst-libav1.0

Package

Name
gst-libav1.0
Purl
pkg:deb/ubuntu/gst-libav1.0?arch=src?distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*

1.16.1-1
1.16.2-1
1.16.2-2

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:20.04:LTS / kino

Package

Name
kino
Purl
pkg:deb/ubuntu/kino?arch=src?distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*

1.3.4+dfsg0-1
1.3.4+dfsg0-1build1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:20.04:LTS / mythtv

Package

Name
mythtv
Purl
pkg:deb/ubuntu/mythtv?arch=src?distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2:30.*

2:30.0+fixes.20190817.5cde0578d8-0ubuntu1
2:30.0+fixes.20190817.5cde0578d8-0ubuntu2
2:30.0+fixes.20190817.5cde0578d8-0ubuntu3

2:31.*

2:31.0+fixes.20200207.35cb9ed0c5-0ubuntu2
2:31.0+fixes.20200323.9579662cdc-0ubuntu1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:20.04:LTS / vice

Package

Name
vice
Purl
pkg:deb/ubuntu/vice?arch=src?distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

3.*

3.3.0.dfsg-2build1
3.4.0.dfsg-1
3.4.0.dfsg-1build1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:22.04:LTS / chromium-browser

Package

Name
chromium-browser
Purl
pkg:deb/ubuntu/chromium-browser?arch=src?distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1:85.*

1:85.0.4183.83-0ubuntu2
1:85.0.4183.83-0ubuntu2.22.04.1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:22.04:LTS / gst-libav1.0

Package

Name
gst-libav1.0
Purl
pkg:deb/ubuntu/gst-libav1.0?arch=src?distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*

1.18.5-1
1.20.0-1
1.20.1-1
1.20.3-0ubuntu1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:22.04:LTS / kino

Package

Name
kino
Purl
pkg:deb/ubuntu/kino?arch=src?distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*

1.3.4+dfsg0-1build2
1.3.4+dfsg0-1.1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:22.04:LTS / mythtv

Package

Name
mythtv
Purl
pkg:deb/ubuntu/mythtv?arch=src?distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2:31.*

2:31.0+fixes.20200323.9579662cdc-0ubuntu9
2:31.0+fixes.20200323.9579662cdc-0ubuntu11

2:32.*

2:32.0+fixes.20220224.56275b303b-0ubuntu3
2:32.0+fixes.20220224.56275b303b-0ubuntu5
2:32.0+fixes.20220325.f69ce764b7-0ubuntu1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:22.04:LTS / vice

Package

Name
vice
Purl
pkg:deb/ubuntu/vice?arch=src?distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

3.*

3.5.0.dfsg-3
3.5.0.dfsg-4
3.6.0.dfsg-1
3.6.1+dfsg-1
3.6.1+dfsg-2

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:24.10 / chromium-browser

Package

Name
chromium-browser
Purl
pkg:deb/ubuntu/chromium-browser?arch=src?distro=oracular

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

Other

2:1snap1-0ubuntu2

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:24.10 / gst-libav1.0

Package

Name
gst-libav1.0
Purl
pkg:deb/ubuntu/gst-libav1.0?arch=src?distro=oracular

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*

1.24.1-1build1
1.24.3-1
1.24.3-2
1.24.4-1
1.24.5-1
1.24.6-1build1
1.24.7-1
1.24.8-1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:24.10 / mythtv

Package

Name
mythtv
Purl
pkg:deb/ubuntu/mythtv?arch=src?distro=oracular

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2:34.*

2:34.0+fixes.20240210.e3e165a1-0ubuntu6

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:24.10 / vice

Package

Name
vice
Purl
pkg:deb/ubuntu/vice?arch=src?distro=oracular

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

3.*

3.7.1+dfsg1-2build3
3.7.1+dfsg1-3

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:24.04:LTS / chromium-browser

Package

Name
chromium-browser
Purl
pkg:deb/ubuntu/chromium-browser?arch=src?distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1:85.*

1:85.0.4183.83-0ubuntu3

Other

2:1snap1-0ubuntu1
2:1snap1-0ubuntu2

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:24.04:LTS / gst-libav1.0

Package

Name
gst-libav1.0
Purl
pkg:deb/ubuntu/gst-libav1.0?arch=src?distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*

1.22.5-1
1.22.6-1
1.22.7-1
1.22.8-1
1.22.10-1
1.24.1-1
1.24.1-1build1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:24.04:LTS / mythtv

Package

Name
mythtv
Purl
pkg:deb/ubuntu/mythtv?arch=src?distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2:33.*

2:33.0+fixes.20230210.026e506-0ubuntu0
2:33.0+fixes.20230210.026e506-0ubuntu2
2:33.0+fixes.20230210.026e506-0ubuntu3
2:33.0+fixes.20230210.026e506-0ubuntu4
2:33.0+fixes.20230210.026e506-0ubuntu5

2:34.*

2:34.0+fixes.20240210.e3e165a1-0ubuntu1
2:34.0+fixes.20240210.e3e165a1-0ubuntu4
2:34.0+fixes.20240210.e3e165a1-0ubuntu5
2:34.0+fixes.20240210.e3e165a1-0ubuntu6

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:24.04:LTS / vice

Package

Name
vice
Purl
pkg:deb/ubuntu/vice?arch=src?distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

3.*

3.7.1+dfsg1-2
3.7.1+dfsg1-2build2
3.7.1+dfsg1-2build3

Ecosystem specific

{
    "ubuntu_priority": "medium"
}