Alpine: multiple ffmpeg packages: security update to 2.8.11-r0

critical Tenable Self-Hosted Container Security Plugin ID 404289

Description

There are packages installed that are affected by multiple vulnerabilities referenced in the following CVEs:

- Integer overflow in the mov_build_index function in libavformat/mov.c in FFmpeg before 2.8.8, 3.0.x before
3.0.3 and 3.1.x before 3.1.1 allows remote attackers to have unspecified impact via vectors involving
sample size. (CVE-2016-6164)

- The jpeg2000_decode_tile function in libavcodec/jpeg2000dec.c in FFmpeg before 2.8.6 allows remote
attackers to cause a denial of service (out-of-bounds array read access) via crafted JPEG 2000 data.
(CVE-2016-2213)

- libswscale/swscale_unscaled.c in FFmpeg before 2.8.6 does not validate certain height values, which allows
remote attackers to cause a denial of service (out-of-bounds array read access) or possibly have
unspecified other impact via a crafted .cine file, related to the bayer_to_rgb24_wrapper and
bayer_to_yv12_wrapper functions. (CVE-2016-2328)

- libavcodec/tiff.c in FFmpeg before 2.8.6 does not properly validate RowsPerStrip values and YCbCr
chrominance subsampling factors, which allows remote attackers to cause a denial of service (out-of-bounds
array access) or possibly have unspecified other impact via a crafted TIFF file, related to the
tiff_decode_tag and decode_frame functions. (CVE-2016-2329)

- libavcodec/gif.c in FFmpeg before 2.8.6 does not properly calculate a buffer size, which allows remote
attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other
impact via a crafted .tga file, related to the gif_image_write_image, gif_encode_init, and
gif_encode_close functions. (CVE-2016-2330)

See Also

https://security.alpinelinux.org/vuln/CVE-2016-10190

https://security.alpinelinux.org/vuln/CVE-2016-10191

https://security.alpinelinux.org/vuln/CVE-2016-10192

https://security.alpinelinux.org/vuln/CVE-2016-2213

https://security.alpinelinux.org/vuln/CVE-2016-2328

https://security.alpinelinux.org/vuln/CVE-2016-2329

https://security.alpinelinux.org/vuln/CVE-2016-2330

https://security.alpinelinux.org/vuln/CVE-2016-6164

https://security.alpinelinux.org/vuln/CVE-2016-6881

https://security.alpinelinux.org/vuln/CVE-2016-7122

https://security.alpinelinux.org/vuln/CVE-2016-7450

https://security.alpinelinux.org/vuln/CVE-2016-7502

https://security.alpinelinux.org/vuln/CVE-2016-7562

https://security.alpinelinux.org/vuln/CVE-2016-7785

https://security.alpinelinux.org/vuln/CVE-2016-7905

https://security.alpinelinux.org/vuln/CVE-2017-5024

https://security.alpinelinux.org/vuln/CVE-2017-5025

Plugin Details

Severity: Critical

ID: 404289

Version: Revision 1.28

Type: Local

Published: 10/31/2023

Updated: 6/29/2026

Supported Sensors: Agentless Assessment, Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 57.12

CVSS v2

Risk Factor: High

Base Score: 7.5

Temporal Score: 5.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS Score Source: CVE-2016-6164

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Temporal Score: 8.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 2/1/2016

Reference Information

CVE: CVE-2016-10190, CVE-2016-10191, CVE-2016-10192, CVE-2016-2213, CVE-2016-2328, CVE-2016-2329, CVE-2016-2330, CVE-2016-6164, CVE-2016-6881, CVE-2016-7122, CVE-2016-7450, CVE-2016-7502, CVE-2016-7562, CVE-2016-7785, CVE-2016-7905, CVE-2017-5024, CVE-2017-5025

BID: 82281, 83332, 84212, 84217, 93163, 94833, 94834, 94835, 94837, 94839, 94841, 95792, 95862, 95986, 95989, 95991