Alpine: ffmpeg2.8: security update to 2.8.7-r0 (deprecated)

critical Tenable Cloud Security Plugin ID 400952

Description

There are packages installed that are affected by multiple vulnerabilities referenced in the following CVEs:

- Integer overflow in the mov_build_index function in libavformat/mov.c in FFmpeg before 2.8.8, 3.0.x before
3.0.3 and 3.1.x before 3.1.1 allows remote attackers to have unspecified impact via vectors involving
sample size. (CVE-2016-6164)

- The zlib_refill function in libavformat/swfdec.c in FFmpeg before 3.1.3 allows remote attackers to cause
an infinite loop denial of service via a crafted SWF file. (CVE-2016-6881)

- The avi_read_nikon function in libavformat/avidec.c in FFmpeg before 3.1.4 is vulnerable to infinite loop
when it decodes an AVI file that has a crafted 'nctg' structure. (CVE-2016-7122)

- The ff_log2_16bit_c function in libavutil/intmath.h in FFmpeg before 3.1.4 is vulnerable to reading out-
of-bounds memory when it decodes a malformed AIFF file. (CVE-2016-7450)

See Also

https://git.alpinelinux.org/aports/commit/?id=00a2dbef659f87f6897cbdd299719f64a679bdcf

https://git.alpinelinux.org/aports/commit/?id=69c95791ab79c2f073015b2ea7e847b27a649257

Plugin Details

Severity: Critical

ID: 400952

Version: Revision 1.24

Type: Local

Published: 8/16/2023

Updated: 7/16/2025

Supported Sensors: Agentless Assessment, Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 57.15

CVSS v2

Risk Factor: High

Base Score: 7.5

Temporal Score: 5.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS Score Source: CVE-2016-6164

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Temporal Score: 8.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 12/26/2016

Vulnerability Publication Date: 9/26/2016

Reference Information

CVE: CVE-2016-6164, CVE-2016-6881, CVE-2016-7122, CVE-2016-7450, CVE-2016-7502, CVE-2016-7562, CVE-2016-7785, CVE-2016-7905

BID: 93163, 94833, 94834, 94835, 94837, 94839, 94841, 95862