UBUNTU-CVE-2018-13305

Source
https://ubuntu.com/security/CVE-2018-13305
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2018/UBUNTU-CVE-2018-13305.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2018-13305
Related
Published
2018-07-05T17:29:00Z
Modified
2024-11-20T12:19:08Z
Severity
  • 8.1 (High) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H CVSS Calculator
Summary
[none]
Details

In FFmpeg 4.0.1, due to a missing check for negative values of the mquant variable, the vc1putblocksclamped function in libavcodec/vc1block.c may trigger an out-of-array access while converting a crafted AVI file to MPEG4, leading to an information disclosure or a denial of service.

References

Affected packages

Ubuntu:Pro:16.04:LTS / oxide-qt

Package

Name
oxide-qt
Purl
pkg:deb/ubuntu/oxide-qt?arch=src?distro=esm-infra/xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*

1.9.5-0ubuntu1
1.10.3-0ubuntu0.15.10.1
1.10.3-0ubuntu0.15.10.2
1.11.3-0ubuntu3
1.11.4-0ubuntu1
1.11.5-0ubuntu1
1.12.5-0ubuntu1
1.12.6-0ubuntu1
1.12.7-0ubuntu1
1.13.6-0ubuntu1
1.14.7-0ubuntu1
1.14.9-0ubuntu0.16.04.1
1.15.7-0ubuntu0.16.04.1
1.15.8-0ubuntu0.16.04.1
1.16.5-0ubuntu0.16.04.1
1.17.7-0ubuntu0.16.04.1
1.17.9-0ubuntu0.16.04.1
1.18.3-0ubuntu0.16.04.1
1.18.5-0ubuntu0.16.04.1
1.19.4-0ubuntu0.16.04.1
1.20.4-0ubuntu0.16.04.1
1.21.5-0ubuntu0.16.04.1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:Pro:16.04:LTS / gst-libav1.0

Package

Name
gst-libav1.0
Purl
pkg:deb/ubuntu/gst-libav1.0?arch=src?distro=esm-apps/xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*

1.6.0-1
1.6.0-2
1.6.1-1
1.6.2-1
1.7.1-1
1.7.2-1
1.7.90-1
1.8.0-1
1.8.1-1~ubuntu1
1.8.2-1~ubuntu1
1.8.3-1ubuntu0.1
1.8.3-1ubuntu0.2

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:Pro:16.04:LTS / mythtv

Package

Name
mythtv
Purl
pkg:deb/ubuntu/mythtv?arch=src?distro=esm-apps/xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2:0.*

2:0.27.1+fixes.20140624.aa822f5-0ubuntu6
2:0.27.1+fixes.20140624.aa822f5-0ubuntu7
2:0.27.1+fixes.20140624.aa822f5-0ubuntu9
2:0.28.0+fixes.20160217.44fd8a6-0ubuntu4
2:0.28.0+fixes.20160229.ae35a28-0ubuntu1
2:0.28.0+fixes.20160321.39e409d-0ubuntu1
2:0.28.0+fixes.20160321.39e409d-0ubuntu2
2:0.28.0+fixes.20160325.2520617-0ubuntu3
2:0.28.0+fixes.20160413.15cf421-0ubuntu1
2:0.28.0+fixes.20160413.15cf421-0ubuntu2
2:0.28.0+fixes.20160413.15cf421-0ubuntu2.16.04.1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:Pro:18.04:LTS / gst-libav1.0

Package

Name
gst-libav1.0
Purl
pkg:deb/ubuntu/gst-libav1.0?arch=src?distro=esm-apps/bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*

1.12.2-1
1.12.3-1
1.12.4-1
1.13.91-1
1.14.0-1
1.14.1-1~ubuntu18.04.1
1.14.4-0ubuntu1~ubuntu18.04.1
1.14.5-0ubuntu1~18.04.1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:Pro:18.04:LTS / mythtv

Package

Name
mythtv
Purl
pkg:deb/ubuntu/mythtv?arch=src?distro=esm-apps/bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2:29.*

2:29.0+fixes.20170728.696806310a-0ubuntu1
2:29.0+fixes.20170728.696806310a-0ubuntu3
2:29.0+fixes.20170728.696806310a-0ubuntu4
2:29.0+fixes.20170728.696806310a-0ubuntu5
2:29.0+fixes.20170728.696806310a-0ubuntu6
2:29.0+fixes.20170728.696806310a-0ubuntu7
2:29.0+fixes.20170728.696806310a-0ubuntu8
2:29.1+fixes.20180220.9b7b962-0ubuntu2
2:29.1+fixes.20180220.9b7b962-0ubuntu3
2:29.1+fixes.20180414.329c235-0ubuntu3

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:20.04:LTS / chromium-browser

Package

Name
chromium-browser
Purl
pkg:deb/ubuntu/chromium-browser?arch=src?distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

77.*

77.0.3865.120-0ubuntu1~snap1
77.0.3865.120-0ubuntu2

78.*

78.0.3904.70-0ubuntu1
78.0.3904.108-0ubuntu1

79.*

79.0.3945.79-0ubuntu1

80.*

80.0.3987.87-0ubuntu1
80.0.3987.162-0ubuntu1
80.0.3987.163-0ubuntu1

81.*

81.0.4044.129-0ubuntu0.20.04.1

83.*

83.0.4103.97-0ubuntu0.20.04.1

84.*

84.0.4147.105-0ubuntu0.20.04.1

1:85.*

1:85.0.4183.83-0ubuntu0.20.04.1
1:85.0.4183.83-0ubuntu0.20.04.2
1:85.0.4183.83-0ubuntu0.20.04.3

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:20.04:LTS / gst-libav1.0

Package

Name
gst-libav1.0
Purl
pkg:deb/ubuntu/gst-libav1.0?arch=src?distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*

1.16.1-1
1.16.2-1
1.16.2-2

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:20.04:LTS / mythtv

Package

Name
mythtv
Purl
pkg:deb/ubuntu/mythtv?arch=src?distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2:30.*

2:30.0+fixes.20190817.5cde0578d8-0ubuntu1
2:30.0+fixes.20190817.5cde0578d8-0ubuntu2
2:30.0+fixes.20190817.5cde0578d8-0ubuntu3

2:31.*

2:31.0+fixes.20200207.35cb9ed0c5-0ubuntu2
2:31.0+fixes.20200323.9579662cdc-0ubuntu1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:22.04:LTS / chromium-browser

Package

Name
chromium-browser
Purl
pkg:deb/ubuntu/chromium-browser?arch=src?distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1:85.*

1:85.0.4183.83-0ubuntu2
1:85.0.4183.83-0ubuntu2.22.04.1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:22.04:LTS / gst-libav1.0

Package

Name
gst-libav1.0
Purl
pkg:deb/ubuntu/gst-libav1.0?arch=src?distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*

1.18.5-1
1.20.0-1
1.20.1-1
1.20.3-0ubuntu1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:22.04:LTS / mythtv

Package

Name
mythtv
Purl
pkg:deb/ubuntu/mythtv?arch=src?distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2:31.*

2:31.0+fixes.20200323.9579662cdc-0ubuntu9
2:31.0+fixes.20200323.9579662cdc-0ubuntu11

2:32.*

2:32.0+fixes.20220224.56275b303b-0ubuntu3
2:32.0+fixes.20220224.56275b303b-0ubuntu5
2:32.0+fixes.20220325.f69ce764b7-0ubuntu1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:24.10 / chromium-browser

Package

Name
chromium-browser
Purl
pkg:deb/ubuntu/chromium-browser?arch=src?distro=oracular

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

Other

2:1snap1-0ubuntu2

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:24.10 / gst-libav1.0

Package

Name
gst-libav1.0
Purl
pkg:deb/ubuntu/gst-libav1.0?arch=src?distro=oracular

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*

1.24.1-1build1
1.24.3-1
1.24.3-2
1.24.4-1
1.24.5-1
1.24.6-1build1
1.24.7-1
1.24.8-1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:24.10 / mythtv

Package

Name
mythtv
Purl
pkg:deb/ubuntu/mythtv?arch=src?distro=oracular

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2:34.*

2:34.0+fixes.20240210.e3e165a1-0ubuntu6

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:24.04:LTS / chromium-browser

Package

Name
chromium-browser
Purl
pkg:deb/ubuntu/chromium-browser?arch=src?distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1:85.*

1:85.0.4183.83-0ubuntu3

Other

2:1snap1-0ubuntu1
2:1snap1-0ubuntu2

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:24.04:LTS / gst-libav1.0

Package

Name
gst-libav1.0
Purl
pkg:deb/ubuntu/gst-libav1.0?arch=src?distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*

1.22.5-1
1.22.6-1
1.22.7-1
1.22.8-1
1.22.10-1
1.24.1-1
1.24.1-1build1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:24.04:LTS / mythtv

Package

Name
mythtv
Purl
pkg:deb/ubuntu/mythtv?arch=src?distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2:33.*

2:33.0+fixes.20230210.026e506-0ubuntu0
2:33.0+fixes.20230210.026e506-0ubuntu2
2:33.0+fixes.20230210.026e506-0ubuntu3
2:33.0+fixes.20230210.026e506-0ubuntu4
2:33.0+fixes.20230210.026e506-0ubuntu5

2:34.*

2:34.0+fixes.20240210.e3e165a1-0ubuntu1
2:34.0+fixes.20240210.e3e165a1-0ubuntu4
2:34.0+fixes.20240210.e3e165a1-0ubuntu5
2:34.0+fixes.20240210.e3e165a1-0ubuntu6

Ecosystem specific

{
    "ubuntu_priority": "medium"
}