Ubuntu Security Notice (C) 2006-2013 Canonical, Inc. / NASL script (C) 2007-2013 Tenable Network Security, Inc.
The remote Ubuntu host is missing one or more security-related patches.
XFOCUS Security Team discovered that the AVI decoder used in xine-lib
did not correctly validate certain headers. By tricking a user into
playing an AVI with malicious headers, an attacker could execute
arbitrary code with the target user's privileges. (CVE-2006-4799)
Multiple integer overflows were discovered in ffmpeg and tools that
contain a copy of ffmpeg (like xine-lib and kino), for several types
of video formats. By tricking a user into running a video player that
uses ffmpeg on a stream with malicious content, an attacker could
execute arbitrary code with the target user's privileges.
Update the affected packages.
Risk factor :
High / CVSS Base Score : 7.5