<?xml version="1.0" encoding="UTF-8"?>
<cvrfdoc xmlns="http://www.icasi.org/CVRF/schema/cvrf/1.1" xmlns:cvrf="http://www.icasi.org/CVRF/schema/cvrf/1.1">
  <DocumentTitle xml:lang="en">Security update for ffmpeg</DocumentTitle>
  <DocumentType>SUSE Patch</DocumentType>
  <DocumentPublisher Type="Vendor">
    <ContactDetails>security@suse.de</ContactDetails>
    <IssuingAuthority>SUSE Security Team</IssuingAuthority>
  </DocumentPublisher>
  <DocumentTracking>
    <Identification>
      <ID>openSUSE-SU-2017:1121-1</ID>
    </Identification>
    <Status>Final</Status>
    <Version>1</Version>
    <RevisionHistory>
      <Revision>
        <Number>1</Number>
        <Date>2017-04-28T06:10:30Z</Date>
        <Description>current</Description>
      </Revision>
    </RevisionHistory>
    <InitialReleaseDate>2017-04-28T06:10:30Z</InitialReleaseDate>
    <CurrentReleaseDate>2017-04-28T06:10:30Z</CurrentReleaseDate>
    <Generator>
      <Engine>cve-database/bin/generate-cvrf.pl</Engine>
      <Date>2017-02-24T01:00:00Z</Date>
    </Generator>
  </DocumentTracking>
  <DocumentNotes>
    <Note Title="Topic" Type="Summary" Ordinal="1" xml:lang="en">Security update for ffmpeg</Note>
    <Note Title="Details" Type="General" Ordinal="2" xml:lang="en">
This update for ffmpeg to version 3.3 fixes several issues.

These security issues were fixed:

- CVE-2016-10190: Heap-based buffer overflow in libavformat/http.c in FFmpeg allowed remote web servers to execute arbitrary code via a negative chunk size in an HTTP response (boo#1022920)
- CVE-2016-10191: Heap-based buffer overflow in libavformat/rtmppkt.c in FFmpeg allowed remote attackers to execute arbitrary code by leveraging failure to check for RTMP packet size mismatches (boo#1022921)
- CVE-2016-10192: Heap-based buffer overflow in ffserver.c in FFmpeg allowed remote attackers to execute arbitrary code by leveraging failure to check chunk size (boo#1022922)
- CVE-2017-7859: FFmpeg had an out-of-bounds write caused by a heap-based buffer overflow related to the ff_h264_slice_context_init function in libavcodec/h264dec.c (bsc#1034183).
- CVE-2017-7862: FFmpeg had an out-of-bounds write caused by a heap-based buffer overflow related to the decode_frame function in libavcodec/pictordec.c (bsc#1034181).
- CVE-2017-7863: FFmpeg had an out-of-bounds write caused by a heap-based buffer overflow related to the decode_frame_common function in libavcodec/pngdec.c (boo#1034179)
- CVE-2017-7865: FFmpeg had an out-of-bounds write caused by a heap-based buffer overflow related to the ipvideo_decode_block_opcode_0xA function in libavcodec/interplayvideo.c and the avcodec_align_dimensions2 function in libavcodec/utils.c (boo#1034177)
- CVE-2017-7866: FFmpeg had an out-of-bounds write caused by a stack-based buffer overflow related to the decode_zbuf function in libavcodec/pngdec.c (boo#1034176)

These non-security issues were fixed:

- Enable ac3 
- Enable mp3 decoding
- EBU R128 implementation now within ffmpeg, not relying on external library anymore
- New video filters 'premultiply', 'readeia608', 'threshold', 'midequalizer'
- Support for spherical videos
- New decoders: 16.8 and 24.0 floating point PCM, XPM
- New demuxers: MIDI Sample Dump Standard, Sample Dump eXchange demuxer
- MJPEG encoding uses Optimal Huffman tables now
- Native Opus encoder
- Support .mov with multiple sample description tables
- Removed the legacy X11 screen grabber, use XCB instead
- Removed asyncts filter (use af_aresample instead)
</Note>
    <Note Title="Terms of Use" Type="Legal Disclaimer" Ordinal="3" xml:lang="en">The CVRF data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).</Note>
  </DocumentNotes>
  <DocumentDistribution xml:lang="en">Copyright SUSE LLC under the Creative Commons License 4.0 with Attribution (CC-BY-4.0)</DocumentDistribution>
  <DocumentReferences>
    <Reference Type="Self">
      <URL>https://lists.opensuse.org/opensuse-updates/2017-04/msg00106.html</URL>
      <Description>E-Mail link for openSUSE-SU-2017:1121-1</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/security/rating/</URL>
      <Description>SUSE Security Ratings</Description>
    </Reference>
  </DocumentReferences>
  <ProductTree xmlns="http://www.icasi.org/CVRF/schema/prod/1.1">
    <Branch Type="Product Family" Name="openSUSE Leap 42.2">
      <Branch Type="Product Name" Name="openSUSE Leap 42.2">
        <FullProductName ProductID="openSUSE Leap 42.2">openSUSE Leap 42.2</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Version" Name="ffmpeg-3.3-6.6.1">
      <FullProductName ProductID="ffmpeg-3.3-6.6.1">ffmpeg-3.3-6.6.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libavcodec-devel-3.3-6.6.1">
      <FullProductName ProductID="libavcodec-devel-3.3-6.6.1">libavcodec-devel-3.3-6.6.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libavcodec57-3.3-6.6.1">
      <FullProductName ProductID="libavcodec57-3.3-6.6.1">libavcodec57-3.3-6.6.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libavcodec57-32bit-3.3-6.6.1">
      <FullProductName ProductID="libavcodec57-32bit-3.3-6.6.1">libavcodec57-32bit-3.3-6.6.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libavdevice-devel-3.3-6.6.1">
      <FullProductName ProductID="libavdevice-devel-3.3-6.6.1">libavdevice-devel-3.3-6.6.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libavdevice57-3.3-6.6.1">
      <FullProductName ProductID="libavdevice57-3.3-6.6.1">libavdevice57-3.3-6.6.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libavdevice57-32bit-3.3-6.6.1">
      <FullProductName ProductID="libavdevice57-32bit-3.3-6.6.1">libavdevice57-32bit-3.3-6.6.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libavfilter-devel-3.3-6.6.1">
      <FullProductName ProductID="libavfilter-devel-3.3-6.6.1">libavfilter-devel-3.3-6.6.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libavfilter6-3.3-6.6.1">
      <FullProductName ProductID="libavfilter6-3.3-6.6.1">libavfilter6-3.3-6.6.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libavfilter6-32bit-3.3-6.6.1">
      <FullProductName ProductID="libavfilter6-32bit-3.3-6.6.1">libavfilter6-32bit-3.3-6.6.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libavformat-devel-3.3-6.6.1">
      <FullProductName ProductID="libavformat-devel-3.3-6.6.1">libavformat-devel-3.3-6.6.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libavformat57-3.3-6.6.1">
      <FullProductName ProductID="libavformat57-3.3-6.6.1">libavformat57-3.3-6.6.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libavformat57-32bit-3.3-6.6.1">
      <FullProductName ProductID="libavformat57-32bit-3.3-6.6.1">libavformat57-32bit-3.3-6.6.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libavresample-devel-3.3-6.6.1">
      <FullProductName ProductID="libavresample-devel-3.3-6.6.1">libavresample-devel-3.3-6.6.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libavresample3-3.3-6.6.1">
      <FullProductName ProductID="libavresample3-3.3-6.6.1">libavresample3-3.3-6.6.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libavresample3-32bit-3.3-6.6.1">
      <FullProductName ProductID="libavresample3-32bit-3.3-6.6.1">libavresample3-32bit-3.3-6.6.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libavutil-devel-3.3-6.6.1">
      <FullProductName ProductID="libavutil-devel-3.3-6.6.1">libavutil-devel-3.3-6.6.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libavutil55-3.3-6.6.1">
      <FullProductName ProductID="libavutil55-3.3-6.6.1">libavutil55-3.3-6.6.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libavutil55-32bit-3.3-6.6.1">
      <FullProductName ProductID="libavutil55-32bit-3.3-6.6.1">libavutil55-32bit-3.3-6.6.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libpostproc-devel-3.3-6.6.1">
      <FullProductName ProductID="libpostproc-devel-3.3-6.6.1">libpostproc-devel-3.3-6.6.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libpostproc54-3.3-6.6.1">
      <FullProductName ProductID="libpostproc54-3.3-6.6.1">libpostproc54-3.3-6.6.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libpostproc54-32bit-3.3-6.6.1">
      <FullProductName ProductID="libpostproc54-32bit-3.3-6.6.1">libpostproc54-32bit-3.3-6.6.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libswresample-devel-3.3-6.6.1">
      <FullProductName ProductID="libswresample-devel-3.3-6.6.1">libswresample-devel-3.3-6.6.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libswresample2-3.3-6.6.1">
      <FullProductName ProductID="libswresample2-3.3-6.6.1">libswresample2-3.3-6.6.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libswresample2-32bit-3.3-6.6.1">
      <FullProductName ProductID="libswresample2-32bit-3.3-6.6.1">libswresample2-32bit-3.3-6.6.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libswscale-devel-3.3-6.6.1">
      <FullProductName ProductID="libswscale-devel-3.3-6.6.1">libswscale-devel-3.3-6.6.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libswscale4-3.3-6.6.1">
      <FullProductName ProductID="libswscale4-3.3-6.6.1">libswscale4-3.3-6.6.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libswscale4-32bit-3.3-6.6.1">
      <FullProductName ProductID="libswscale4-32bit-3.3-6.6.1">libswscale4-32bit-3.3-6.6.1</FullProductName>
    </Branch>
    <Relationship ProductReference="ffmpeg-3.3-6.6.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.2">
      <FullProductName ProductID="openSUSE Leap 42.2:ffmpeg-3.3-6.6.1">ffmpeg-3.3-6.6.1 as a component of openSUSE Leap 42.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="libavcodec-devel-3.3-6.6.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.2">
      <FullProductName ProductID="openSUSE Leap 42.2:libavcodec-devel-3.3-6.6.1">libavcodec-devel-3.3-6.6.1 as a component of openSUSE Leap 42.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="libavcodec57-3.3-6.6.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.2">
      <FullProductName ProductID="openSUSE Leap 42.2:libavcodec57-3.3-6.6.1">libavcodec57-3.3-6.6.1 as a component of openSUSE Leap 42.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="libavcodec57-32bit-3.3-6.6.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.2">
      <FullProductName ProductID="openSUSE Leap 42.2:libavcodec57-32bit-3.3-6.6.1">libavcodec57-32bit-3.3-6.6.1 as a component of openSUSE Leap 42.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="libavdevice-devel-3.3-6.6.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.2">
      <FullProductName ProductID="openSUSE Leap 42.2:libavdevice-devel-3.3-6.6.1">libavdevice-devel-3.3-6.6.1 as a component of openSUSE Leap 42.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="libavdevice57-3.3-6.6.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.2">
      <FullProductName ProductID="openSUSE Leap 42.2:libavdevice57-3.3-6.6.1">libavdevice57-3.3-6.6.1 as a component of openSUSE Leap 42.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="libavdevice57-32bit-3.3-6.6.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.2">
      <FullProductName ProductID="openSUSE Leap 42.2:libavdevice57-32bit-3.3-6.6.1">libavdevice57-32bit-3.3-6.6.1 as a component of openSUSE Leap 42.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="libavfilter-devel-3.3-6.6.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.2">
      <FullProductName ProductID="openSUSE Leap 42.2:libavfilter-devel-3.3-6.6.1">libavfilter-devel-3.3-6.6.1 as a component of openSUSE Leap 42.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="libavfilter6-3.3-6.6.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.2">
      <FullProductName ProductID="openSUSE Leap 42.2:libavfilter6-3.3-6.6.1">libavfilter6-3.3-6.6.1 as a component of openSUSE Leap 42.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="libavfilter6-32bit-3.3-6.6.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.2">
      <FullProductName ProductID="openSUSE Leap 42.2:libavfilter6-32bit-3.3-6.6.1">libavfilter6-32bit-3.3-6.6.1 as a component of openSUSE Leap 42.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="libavformat-devel-3.3-6.6.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.2">
      <FullProductName ProductID="openSUSE Leap 42.2:libavformat-devel-3.3-6.6.1">libavformat-devel-3.3-6.6.1 as a component of openSUSE Leap 42.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="libavformat57-3.3-6.6.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.2">
      <FullProductName ProductID="openSUSE Leap 42.2:libavformat57-3.3-6.6.1">libavformat57-3.3-6.6.1 as a component of openSUSE Leap 42.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="libavformat57-32bit-3.3-6.6.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.2">
      <FullProductName ProductID="openSUSE Leap 42.2:libavformat57-32bit-3.3-6.6.1">libavformat57-32bit-3.3-6.6.1 as a component of openSUSE Leap 42.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="libavresample-devel-3.3-6.6.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.2">
      <FullProductName ProductID="openSUSE Leap 42.2:libavresample-devel-3.3-6.6.1">libavresample-devel-3.3-6.6.1 as a component of openSUSE Leap 42.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="libavresample3-3.3-6.6.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.2">
      <FullProductName ProductID="openSUSE Leap 42.2:libavresample3-3.3-6.6.1">libavresample3-3.3-6.6.1 as a component of openSUSE Leap 42.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="libavresample3-32bit-3.3-6.6.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.2">
      <FullProductName ProductID="openSUSE Leap 42.2:libavresample3-32bit-3.3-6.6.1">libavresample3-32bit-3.3-6.6.1 as a component of openSUSE Leap 42.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="libavutil-devel-3.3-6.6.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.2">
      <FullProductName ProductID="openSUSE Leap 42.2:libavutil-devel-3.3-6.6.1">libavutil-devel-3.3-6.6.1 as a component of openSUSE Leap 42.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="libavutil55-3.3-6.6.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.2">
      <FullProductName ProductID="openSUSE Leap 42.2:libavutil55-3.3-6.6.1">libavutil55-3.3-6.6.1 as a component of openSUSE Leap 42.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="libavutil55-32bit-3.3-6.6.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.2">
      <FullProductName ProductID="openSUSE Leap 42.2:libavutil55-32bit-3.3-6.6.1">libavutil55-32bit-3.3-6.6.1 as a component of openSUSE Leap 42.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="libpostproc-devel-3.3-6.6.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.2">
      <FullProductName ProductID="openSUSE Leap 42.2:libpostproc-devel-3.3-6.6.1">libpostproc-devel-3.3-6.6.1 as a component of openSUSE Leap 42.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="libpostproc54-3.3-6.6.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.2">
      <FullProductName ProductID="openSUSE Leap 42.2:libpostproc54-3.3-6.6.1">libpostproc54-3.3-6.6.1 as a component of openSUSE Leap 42.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="libpostproc54-32bit-3.3-6.6.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.2">
      <FullProductName ProductID="openSUSE Leap 42.2:libpostproc54-32bit-3.3-6.6.1">libpostproc54-32bit-3.3-6.6.1 as a component of openSUSE Leap 42.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="libswresample-devel-3.3-6.6.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.2">
      <FullProductName ProductID="openSUSE Leap 42.2:libswresample-devel-3.3-6.6.1">libswresample-devel-3.3-6.6.1 as a component of openSUSE Leap 42.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="libswresample2-3.3-6.6.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.2">
      <FullProductName ProductID="openSUSE Leap 42.2:libswresample2-3.3-6.6.1">libswresample2-3.3-6.6.1 as a component of openSUSE Leap 42.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="libswresample2-32bit-3.3-6.6.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.2">
      <FullProductName ProductID="openSUSE Leap 42.2:libswresample2-32bit-3.3-6.6.1">libswresample2-32bit-3.3-6.6.1 as a component of openSUSE Leap 42.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="libswscale-devel-3.3-6.6.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.2">
      <FullProductName ProductID="openSUSE Leap 42.2:libswscale-devel-3.3-6.6.1">libswscale-devel-3.3-6.6.1 as a component of openSUSE Leap 42.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="libswscale4-3.3-6.6.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.2">
      <FullProductName ProductID="openSUSE Leap 42.2:libswscale4-3.3-6.6.1">libswscale4-3.3-6.6.1 as a component of openSUSE Leap 42.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="libswscale4-32bit-3.3-6.6.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.2">
      <FullProductName ProductID="openSUSE Leap 42.2:libswscale4-32bit-3.3-6.6.1">libswscale4-32bit-3.3-6.6.1 as a component of openSUSE Leap 42.2</FullProductName>
    </Relationship>
  </ProductTree>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="1">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Heap-based buffer overflow in libavformat/http.c in FFmpeg before 2.8.10, 3.0.x before 3.0.5, 3.1.x before 3.1.6, and 3.2.x before 3.2.2 allows remote web servers to execute arbitrary code via a negative chunk size in an HTTP response.</Note>
    </Notes>
    <CVE>CVE-2016-10190</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 42.2:ffmpeg-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libavcodec-devel-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libavcodec57-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libavcodec57-32bit-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libavdevice-devel-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libavdevice57-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libavdevice57-32bit-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libavfilter-devel-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libavfilter6-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libavfilter6-32bit-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libavformat-devel-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libavformat57-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libavformat57-32bit-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libavresample-devel-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libavresample3-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libavresample3-32bit-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libavutil-devel-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libavutil55-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libavutil55-32bit-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libpostproc-devel-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libpostproc54-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libpostproc54-32bit-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libswresample-devel-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libswresample2-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libswresample2-32bit-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libswscale-devel-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libswscale4-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libswscale4-32bit-3.3-6.6.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>https://lists.opensuse.org/opensuse-updates/2017-04/msg00106.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-10190.html</URL>
        <Description>CVE-2016-10190</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1022920</URL>
        <Description>SUSE Bug 1022920</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="2">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Heap-based buffer overflow in libavformat/rtmppkt.c in FFmpeg before 2.8.10, 3.0.x before 3.0.5, 3.1.x before 3.1.6, and 3.2.x before 3.2.2 allows remote attackers to execute arbitrary code by leveraging failure to check for RTMP packet size mismatches.</Note>
    </Notes>
    <CVE>CVE-2016-10191</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 42.2:ffmpeg-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libavcodec-devel-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libavcodec57-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libavcodec57-32bit-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libavdevice-devel-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libavdevice57-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libavdevice57-32bit-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libavfilter-devel-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libavfilter6-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libavfilter6-32bit-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libavformat-devel-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libavformat57-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libavformat57-32bit-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libavresample-devel-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libavresample3-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libavresample3-32bit-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libavutil-devel-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libavutil55-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libavutil55-32bit-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libpostproc-devel-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libpostproc54-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libpostproc54-32bit-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libswresample-devel-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libswresample2-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libswresample2-32bit-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libswscale-devel-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libswscale4-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libswscale4-32bit-3.3-6.6.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>https://lists.opensuse.org/opensuse-updates/2017-04/msg00106.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-10191.html</URL>
        <Description>CVE-2016-10191</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1022921</URL>
        <Description>SUSE Bug 1022921</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="3">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Heap-based buffer overflow in ffserver.c in FFmpeg before 2.8.10, 3.0.x before 3.0.5, 3.1.x before 3.1.6, and 3.2.x before 3.2.2 allows remote attackers to execute arbitrary code by leveraging failure to check chunk size.</Note>
    </Notes>
    <CVE>CVE-2016-10192</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 42.2:ffmpeg-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libavcodec-devel-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libavcodec57-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libavcodec57-32bit-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libavdevice-devel-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libavdevice57-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libavdevice57-32bit-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libavfilter-devel-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libavfilter6-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libavfilter6-32bit-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libavformat-devel-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libavformat57-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libavformat57-32bit-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libavresample-devel-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libavresample3-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libavresample3-32bit-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libavutil-devel-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libavutil55-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libavutil55-32bit-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libpostproc-devel-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libpostproc54-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libpostproc54-32bit-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libswresample-devel-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libswresample2-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libswresample2-32bit-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libswscale-devel-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libswscale4-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libswscale4-32bit-3.3-6.6.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>https://lists.opensuse.org/opensuse-updates/2017-04/msg00106.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-10192.html</URL>
        <Description>CVE-2016-10192</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1022922</URL>
        <Description>SUSE Bug 1022922</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="4">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">FFmpeg before 2017-03-05 has an out-of-bounds write caused by a heap-based buffer overflow related to the ff_h264_slice_context_init function in libavcodec/h264dec.c.</Note>
    </Notes>
    <CVE>CVE-2017-7859</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 42.2:ffmpeg-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libavcodec-devel-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libavcodec57-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libavcodec57-32bit-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libavdevice-devel-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libavdevice57-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libavdevice57-32bit-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libavfilter-devel-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libavfilter6-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libavfilter6-32bit-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libavformat-devel-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libavformat57-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libavformat57-32bit-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libavresample-devel-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libavresample3-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libavresample3-32bit-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libavutil-devel-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libavutil55-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libavutil55-32bit-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libpostproc-devel-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libpostproc54-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libpostproc54-32bit-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libswresample-devel-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libswresample2-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libswresample2-32bit-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libswscale-devel-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libswscale4-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libswscale4-32bit-3.3-6.6.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>https://lists.opensuse.org/opensuse-updates/2017-04/msg00106.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2017-7859.html</URL>
        <Description>CVE-2017-7859</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1034183</URL>
        <Description>SUSE Bug 1034183</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="5">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">FFmpeg before 2017-02-07 has an out-of-bounds write caused by a heap-based buffer overflow related to the decode_frame function in libavcodec/pictordec.c.</Note>
    </Notes>
    <CVE>CVE-2017-7862</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 42.2:ffmpeg-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libavcodec-devel-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libavcodec57-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libavcodec57-32bit-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libavdevice-devel-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libavdevice57-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libavdevice57-32bit-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libavfilter-devel-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libavfilter6-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libavfilter6-32bit-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libavformat-devel-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libavformat57-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libavformat57-32bit-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libavresample-devel-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libavresample3-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libavresample3-32bit-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libavutil-devel-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libavutil55-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libavutil55-32bit-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libpostproc-devel-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libpostproc54-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libpostproc54-32bit-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libswresample-devel-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libswresample2-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libswresample2-32bit-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libswscale-devel-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libswscale4-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libswscale4-32bit-3.3-6.6.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>https://lists.opensuse.org/opensuse-updates/2017-04/msg00106.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2017-7862.html</URL>
        <Description>CVE-2017-7862</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1034181</URL>
        <Description>SUSE Bug 1034181</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="6">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">FFmpeg before 2017-02-04 has an out-of-bounds write caused by a heap-based buffer overflow related to the decode_frame_common function in libavcodec/pngdec.c.</Note>
    </Notes>
    <CVE>CVE-2017-7863</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 42.2:ffmpeg-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libavcodec-devel-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libavcodec57-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libavcodec57-32bit-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libavdevice-devel-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libavdevice57-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libavdevice57-32bit-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libavfilter-devel-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libavfilter6-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libavfilter6-32bit-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libavformat-devel-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libavformat57-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libavformat57-32bit-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libavresample-devel-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libavresample3-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libavresample3-32bit-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libavutil-devel-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libavutil55-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libavutil55-32bit-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libpostproc-devel-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libpostproc54-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libpostproc54-32bit-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libswresample-devel-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libswresample2-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libswresample2-32bit-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libswscale-devel-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libswscale4-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libswscale4-32bit-3.3-6.6.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>https://lists.opensuse.org/opensuse-updates/2017-04/msg00106.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2017-7863.html</URL>
        <Description>CVE-2017-7863</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1034179</URL>
        <Description>SUSE Bug 1034179</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="7">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">FFmpeg before 2017-01-24 has an out-of-bounds write caused by a heap-based buffer overflow related to the ipvideo_decode_block_opcode_0xA function in libavcodec/interplayvideo.c and the avcodec_align_dimensions2 function in libavcodec/utils.c.</Note>
    </Notes>
    <CVE>CVE-2017-7865</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 42.2:ffmpeg-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libavcodec-devel-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libavcodec57-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libavcodec57-32bit-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libavdevice-devel-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libavdevice57-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libavdevice57-32bit-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libavfilter-devel-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libavfilter6-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libavfilter6-32bit-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libavformat-devel-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libavformat57-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libavformat57-32bit-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libavresample-devel-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libavresample3-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libavresample3-32bit-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libavutil-devel-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libavutil55-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libavutil55-32bit-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libpostproc-devel-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libpostproc54-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libpostproc54-32bit-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libswresample-devel-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libswresample2-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libswresample2-32bit-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libswscale-devel-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libswscale4-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libswscale4-32bit-3.3-6.6.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>https://lists.opensuse.org/opensuse-updates/2017-04/msg00106.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2017-7865.html</URL>
        <Description>CVE-2017-7865</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1034177</URL>
        <Description>SUSE Bug 1034177</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="8">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">FFmpeg before 2017-01-23 has an out-of-bounds write caused by a stack-based buffer overflow related to the decode_zbuf function in libavcodec/pngdec.c.</Note>
    </Notes>
    <CVE>CVE-2017-7866</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 42.2:ffmpeg-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libavcodec-devel-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libavcodec57-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libavcodec57-32bit-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libavdevice-devel-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libavdevice57-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libavdevice57-32bit-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libavfilter-devel-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libavfilter6-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libavfilter6-32bit-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libavformat-devel-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libavformat57-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libavformat57-32bit-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libavresample-devel-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libavresample3-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libavresample3-32bit-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libavutil-devel-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libavutil55-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libavutil55-32bit-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libpostproc-devel-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libpostproc54-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libpostproc54-32bit-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libswresample-devel-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libswresample2-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libswresample2-32bit-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libswscale-devel-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libswscale4-3.3-6.6.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libswscale4-32bit-3.3-6.6.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>https://lists.opensuse.org/opensuse-updates/2017-04/msg00106.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2017-7866.html</URL>
        <Description>CVE-2017-7866</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1034176</URL>
        <Description>SUSE Bug 1034176</Description>
      </Reference>
    </References>
  </Vulnerability>
</cvrfdoc>
