<?xml version="1.0" encoding="UTF-8"?>
<cvrfdoc xmlns="http://www.icasi.org/CVRF/schema/cvrf/1.1" xmlns:cvrf="http://www.icasi.org/CVRF/schema/cvrf/1.1">
  <DocumentTitle xml:lang="en">Security update for ffmpeg</DocumentTitle>
  <DocumentType>SUSE Patch</DocumentType>
  <DocumentPublisher Type="Vendor">
    <ContactDetails>security@suse.de</ContactDetails>
    <IssuingAuthority>SUSE Security Team</IssuingAuthority>
  </DocumentPublisher>
  <DocumentTracking>
    <Identification>
      <ID>openSUSE-SU-2017:1531-1</ID>
    </Identification>
    <Status>Final</Status>
    <Version>1</Version>
    <RevisionHistory>
      <Revision>
        <Number>1</Number>
        <Date>2017-06-11T09:31:47Z</Date>
        <Description>current</Description>
      </Revision>
    </RevisionHistory>
    <InitialReleaseDate>2017-06-11T09:31:47Z</InitialReleaseDate>
    <CurrentReleaseDate>2017-06-11T09:31:47Z</CurrentReleaseDate>
    <Generator>
      <Engine>cve-database/bin/generate-cvrf.pl</Engine>
      <Date>2017-02-24T01:00:00Z</Date>
    </Generator>
  </DocumentTracking>
  <DocumentNotes>
    <Note Title="Topic" Type="Summary" Ordinal="1" xml:lang="en">Security update for ffmpeg</Note>
    <Note Title="Details" Type="General" Ordinal="2" xml:lang="en">This update of ffmpeg to version 3.1.8 fixes the following security issues:

- CVE-2016-9561: DoS through huge memory allocation (bsc#1015120)
- CVE-2016-10191: remote code execution vulnerability (bsc#1022921)
- CVE-2016-10192: remote code execution vulnerability (bsc#1022922)
- CVE-2017-5024: Heap overflow
- CVE-2017-5025: Heap overflow
</Note>
    <Note Title="Terms of Use" Type="Legal Disclaimer" Ordinal="3" xml:lang="en">The CVRF data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).</Note>
    <Note Title="Patchnames" Type="Details" Ordinal="4" xml:lang="en">openSUSE-2017-673</Note>
  </DocumentNotes>
  <DocumentDistribution xml:lang="en">Copyright SUSE LLC under the Creative Commons License 4.0 with Attribution (CC-BY-4.0)</DocumentDistribution>
  <DocumentReferences>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/security/rating/</URL>
      <Description>SUSE Security Ratings</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1015120</URL>
      <Description>SUSE Bug 1015120</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1022921</URL>
      <Description>SUSE Bug 1022921</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1022922</URL>
      <Description>SUSE Bug 1022922</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2016-10191/</URL>
      <Description>SUSE CVE CVE-2016-10191 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2016-10192/</URL>
      <Description>SUSE CVE CVE-2016-10192 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2016-9561/</URL>
      <Description>SUSE CVE CVE-2016-9561 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2017-5024/</URL>
      <Description>SUSE CVE CVE-2017-5024 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2017-5025/</URL>
      <Description>SUSE CVE CVE-2017-5025 page</Description>
    </Reference>
  </DocumentReferences>
  <ProductTree xmlns="http://www.icasi.org/CVRF/schema/prod/1.1">
    <Branch Type="Product Family" Name="SUSE Package Hub 12 SP2">
      <Branch Type="Product Name" Name="SUSE Package Hub 12 SP2">
        <FullProductName ProductID="SUSE Package Hub 12 SP2" CPE="cpe:/o:suse:packagehub:12:sp2">SUSE Package Hub 12 SP2</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Version" Name="ffmpeg-3.1.8-8.1">
      <FullProductName ProductID="ffmpeg-3.1.8-8.1">ffmpeg-3.1.8-8.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libavcodec-devel-3.1.8-8.1">
      <FullProductName ProductID="libavcodec-devel-3.1.8-8.1">libavcodec-devel-3.1.8-8.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libavcodec57-3.1.8-8.1">
      <FullProductName ProductID="libavcodec57-3.1.8-8.1">libavcodec57-3.1.8-8.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libavdevice-devel-3.1.8-8.1">
      <FullProductName ProductID="libavdevice-devel-3.1.8-8.1">libavdevice-devel-3.1.8-8.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libavdevice57-3.1.8-8.1">
      <FullProductName ProductID="libavdevice57-3.1.8-8.1">libavdevice57-3.1.8-8.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libavfilter-devel-3.1.8-8.1">
      <FullProductName ProductID="libavfilter-devel-3.1.8-8.1">libavfilter-devel-3.1.8-8.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libavfilter6-3.1.8-8.1">
      <FullProductName ProductID="libavfilter6-3.1.8-8.1">libavfilter6-3.1.8-8.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libavformat-devel-3.1.8-8.1">
      <FullProductName ProductID="libavformat-devel-3.1.8-8.1">libavformat-devel-3.1.8-8.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libavformat57-3.1.8-8.1">
      <FullProductName ProductID="libavformat57-3.1.8-8.1">libavformat57-3.1.8-8.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libavresample-devel-3.1.8-8.1">
      <FullProductName ProductID="libavresample-devel-3.1.8-8.1">libavresample-devel-3.1.8-8.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libavresample3-3.1.8-8.1">
      <FullProductName ProductID="libavresample3-3.1.8-8.1">libavresample3-3.1.8-8.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libavutil-devel-3.1.8-8.1">
      <FullProductName ProductID="libavutil-devel-3.1.8-8.1">libavutil-devel-3.1.8-8.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libavutil55-3.1.8-8.1">
      <FullProductName ProductID="libavutil55-3.1.8-8.1">libavutil55-3.1.8-8.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libpostproc-devel-3.1.8-8.1">
      <FullProductName ProductID="libpostproc-devel-3.1.8-8.1">libpostproc-devel-3.1.8-8.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libpostproc54-3.1.8-8.1">
      <FullProductName ProductID="libpostproc54-3.1.8-8.1">libpostproc54-3.1.8-8.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libswresample-devel-3.1.8-8.1">
      <FullProductName ProductID="libswresample-devel-3.1.8-8.1">libswresample-devel-3.1.8-8.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libswresample2-3.1.8-8.1">
      <FullProductName ProductID="libswresample2-3.1.8-8.1">libswresample2-3.1.8-8.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libswscale-devel-3.1.8-8.1">
      <FullProductName ProductID="libswscale-devel-3.1.8-8.1">libswscale-devel-3.1.8-8.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libswscale4-3.1.8-8.1">
      <FullProductName ProductID="libswscale4-3.1.8-8.1">libswscale4-3.1.8-8.1</FullProductName>
    </Branch>
    <Relationship ProductReference="ffmpeg-3.1.8-8.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Package Hub 12 SP2">
      <FullProductName ProductID="SUSE Package Hub 12 SP2:ffmpeg-3.1.8-8.1">ffmpeg-3.1.8-8.1 as a component of SUSE Package Hub 12 SP2</FullProductName>
    </Relationship>
    <Relationship ProductReference="libavcodec-devel-3.1.8-8.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Package Hub 12 SP2">
      <FullProductName ProductID="SUSE Package Hub 12 SP2:libavcodec-devel-3.1.8-8.1">libavcodec-devel-3.1.8-8.1 as a component of SUSE Package Hub 12 SP2</FullProductName>
    </Relationship>
    <Relationship ProductReference="libavcodec57-3.1.8-8.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Package Hub 12 SP2">
      <FullProductName ProductID="SUSE Package Hub 12 SP2:libavcodec57-3.1.8-8.1">libavcodec57-3.1.8-8.1 as a component of SUSE Package Hub 12 SP2</FullProductName>
    </Relationship>
    <Relationship ProductReference="libavdevice-devel-3.1.8-8.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Package Hub 12 SP2">
      <FullProductName ProductID="SUSE Package Hub 12 SP2:libavdevice-devel-3.1.8-8.1">libavdevice-devel-3.1.8-8.1 as a component of SUSE Package Hub 12 SP2</FullProductName>
    </Relationship>
    <Relationship ProductReference="libavdevice57-3.1.8-8.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Package Hub 12 SP2">
      <FullProductName ProductID="SUSE Package Hub 12 SP2:libavdevice57-3.1.8-8.1">libavdevice57-3.1.8-8.1 as a component of SUSE Package Hub 12 SP2</FullProductName>
    </Relationship>
    <Relationship ProductReference="libavfilter-devel-3.1.8-8.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Package Hub 12 SP2">
      <FullProductName ProductID="SUSE Package Hub 12 SP2:libavfilter-devel-3.1.8-8.1">libavfilter-devel-3.1.8-8.1 as a component of SUSE Package Hub 12 SP2</FullProductName>
    </Relationship>
    <Relationship ProductReference="libavfilter6-3.1.8-8.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Package Hub 12 SP2">
      <FullProductName ProductID="SUSE Package Hub 12 SP2:libavfilter6-3.1.8-8.1">libavfilter6-3.1.8-8.1 as a component of SUSE Package Hub 12 SP2</FullProductName>
    </Relationship>
    <Relationship ProductReference="libavformat-devel-3.1.8-8.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Package Hub 12 SP2">
      <FullProductName ProductID="SUSE Package Hub 12 SP2:libavformat-devel-3.1.8-8.1">libavformat-devel-3.1.8-8.1 as a component of SUSE Package Hub 12 SP2</FullProductName>
    </Relationship>
    <Relationship ProductReference="libavformat57-3.1.8-8.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Package Hub 12 SP2">
      <FullProductName ProductID="SUSE Package Hub 12 SP2:libavformat57-3.1.8-8.1">libavformat57-3.1.8-8.1 as a component of SUSE Package Hub 12 SP2</FullProductName>
    </Relationship>
    <Relationship ProductReference="libavresample-devel-3.1.8-8.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Package Hub 12 SP2">
      <FullProductName ProductID="SUSE Package Hub 12 SP2:libavresample-devel-3.1.8-8.1">libavresample-devel-3.1.8-8.1 as a component of SUSE Package Hub 12 SP2</FullProductName>
    </Relationship>
    <Relationship ProductReference="libavresample3-3.1.8-8.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Package Hub 12 SP2">
      <FullProductName ProductID="SUSE Package Hub 12 SP2:libavresample3-3.1.8-8.1">libavresample3-3.1.8-8.1 as a component of SUSE Package Hub 12 SP2</FullProductName>
    </Relationship>
    <Relationship ProductReference="libavutil-devel-3.1.8-8.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Package Hub 12 SP2">
      <FullProductName ProductID="SUSE Package Hub 12 SP2:libavutil-devel-3.1.8-8.1">libavutil-devel-3.1.8-8.1 as a component of SUSE Package Hub 12 SP2</FullProductName>
    </Relationship>
    <Relationship ProductReference="libavutil55-3.1.8-8.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Package Hub 12 SP2">
      <FullProductName ProductID="SUSE Package Hub 12 SP2:libavutil55-3.1.8-8.1">libavutil55-3.1.8-8.1 as a component of SUSE Package Hub 12 SP2</FullProductName>
    </Relationship>
    <Relationship ProductReference="libpostproc-devel-3.1.8-8.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Package Hub 12 SP2">
      <FullProductName ProductID="SUSE Package Hub 12 SP2:libpostproc-devel-3.1.8-8.1">libpostproc-devel-3.1.8-8.1 as a component of SUSE Package Hub 12 SP2</FullProductName>
    </Relationship>
    <Relationship ProductReference="libpostproc54-3.1.8-8.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Package Hub 12 SP2">
      <FullProductName ProductID="SUSE Package Hub 12 SP2:libpostproc54-3.1.8-8.1">libpostproc54-3.1.8-8.1 as a component of SUSE Package Hub 12 SP2</FullProductName>
    </Relationship>
    <Relationship ProductReference="libswresample-devel-3.1.8-8.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Package Hub 12 SP2">
      <FullProductName ProductID="SUSE Package Hub 12 SP2:libswresample-devel-3.1.8-8.1">libswresample-devel-3.1.8-8.1 as a component of SUSE Package Hub 12 SP2</FullProductName>
    </Relationship>
    <Relationship ProductReference="libswresample2-3.1.8-8.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Package Hub 12 SP2">
      <FullProductName ProductID="SUSE Package Hub 12 SP2:libswresample2-3.1.8-8.1">libswresample2-3.1.8-8.1 as a component of SUSE Package Hub 12 SP2</FullProductName>
    </Relationship>
    <Relationship ProductReference="libswscale-devel-3.1.8-8.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Package Hub 12 SP2">
      <FullProductName ProductID="SUSE Package Hub 12 SP2:libswscale-devel-3.1.8-8.1">libswscale-devel-3.1.8-8.1 as a component of SUSE Package Hub 12 SP2</FullProductName>
    </Relationship>
    <Relationship ProductReference="libswscale4-3.1.8-8.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Package Hub 12 SP2">
      <FullProductName ProductID="SUSE Package Hub 12 SP2:libswscale4-3.1.8-8.1">libswscale4-3.1.8-8.1 as a component of SUSE Package Hub 12 SP2</FullProductName>
    </Relationship>
  </ProductTree>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="1">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Heap-based buffer overflow in libavformat/rtmppkt.c in FFmpeg before 2.8.10, 3.0.x before 3.0.5, 3.1.x before 3.1.6, and 3.2.x before 3.2.2 allows remote attackers to execute arbitrary code by leveraging failure to check for RTMP packet size mismatches.</Note>
    </Notes>
    <CVE>CVE-2016-10191</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Package Hub 12 SP2:ffmpeg-3.1.8-8.1</ProductID>
        <ProductID>SUSE Package Hub 12 SP2:libavcodec-devel-3.1.8-8.1</ProductID>
        <ProductID>SUSE Package Hub 12 SP2:libavcodec57-3.1.8-8.1</ProductID>
        <ProductID>SUSE Package Hub 12 SP2:libavdevice-devel-3.1.8-8.1</ProductID>
        <ProductID>SUSE Package Hub 12 SP2:libavdevice57-3.1.8-8.1</ProductID>
        <ProductID>SUSE Package Hub 12 SP2:libavfilter-devel-3.1.8-8.1</ProductID>
        <ProductID>SUSE Package Hub 12 SP2:libavfilter6-3.1.8-8.1</ProductID>
        <ProductID>SUSE Package Hub 12 SP2:libavformat-devel-3.1.8-8.1</ProductID>
        <ProductID>SUSE Package Hub 12 SP2:libavformat57-3.1.8-8.1</ProductID>
        <ProductID>SUSE Package Hub 12 SP2:libavresample-devel-3.1.8-8.1</ProductID>
        <ProductID>SUSE Package Hub 12 SP2:libavresample3-3.1.8-8.1</ProductID>
        <ProductID>SUSE Package Hub 12 SP2:libavutil-devel-3.1.8-8.1</ProductID>
        <ProductID>SUSE Package Hub 12 SP2:libavutil55-3.1.8-8.1</ProductID>
        <ProductID>SUSE Package Hub 12 SP2:libpostproc-devel-3.1.8-8.1</ProductID>
        <ProductID>SUSE Package Hub 12 SP2:libpostproc54-3.1.8-8.1</ProductID>
        <ProductID>SUSE Package Hub 12 SP2:libswresample-devel-3.1.8-8.1</ProductID>
        <ProductID>SUSE Package Hub 12 SP2:libswresample2-3.1.8-8.1</ProductID>
        <ProductID>SUSE Package Hub 12 SP2:libswscale-devel-3.1.8-8.1</ProductID>
        <ProductID>SUSE Package Hub 12 SP2:libswscale4-3.1.8-8.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>7.5</BaseScore>
        <Vector>AV:N/AC:L/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-10191.html</URL>
        <Description>CVE-2016-10191</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1022921</URL>
        <Description>SUSE Bug 1022921</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="2">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Heap-based buffer overflow in ffserver.c in FFmpeg before 2.8.10, 3.0.x before 3.0.5, 3.1.x before 3.1.6, and 3.2.x before 3.2.2 allows remote attackers to execute arbitrary code by leveraging failure to check chunk size.</Note>
    </Notes>
    <CVE>CVE-2016-10192</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Package Hub 12 SP2:ffmpeg-3.1.8-8.1</ProductID>
        <ProductID>SUSE Package Hub 12 SP2:libavcodec-devel-3.1.8-8.1</ProductID>
        <ProductID>SUSE Package Hub 12 SP2:libavcodec57-3.1.8-8.1</ProductID>
        <ProductID>SUSE Package Hub 12 SP2:libavdevice-devel-3.1.8-8.1</ProductID>
        <ProductID>SUSE Package Hub 12 SP2:libavdevice57-3.1.8-8.1</ProductID>
        <ProductID>SUSE Package Hub 12 SP2:libavfilter-devel-3.1.8-8.1</ProductID>
        <ProductID>SUSE Package Hub 12 SP2:libavfilter6-3.1.8-8.1</ProductID>
        <ProductID>SUSE Package Hub 12 SP2:libavformat-devel-3.1.8-8.1</ProductID>
        <ProductID>SUSE Package Hub 12 SP2:libavformat57-3.1.8-8.1</ProductID>
        <ProductID>SUSE Package Hub 12 SP2:libavresample-devel-3.1.8-8.1</ProductID>
        <ProductID>SUSE Package Hub 12 SP2:libavresample3-3.1.8-8.1</ProductID>
        <ProductID>SUSE Package Hub 12 SP2:libavutil-devel-3.1.8-8.1</ProductID>
        <ProductID>SUSE Package Hub 12 SP2:libavutil55-3.1.8-8.1</ProductID>
        <ProductID>SUSE Package Hub 12 SP2:libpostproc-devel-3.1.8-8.1</ProductID>
        <ProductID>SUSE Package Hub 12 SP2:libpostproc54-3.1.8-8.1</ProductID>
        <ProductID>SUSE Package Hub 12 SP2:libswresample-devel-3.1.8-8.1</ProductID>
        <ProductID>SUSE Package Hub 12 SP2:libswresample2-3.1.8-8.1</ProductID>
        <ProductID>SUSE Package Hub 12 SP2:libswscale-devel-3.1.8-8.1</ProductID>
        <ProductID>SUSE Package Hub 12 SP2:libswscale4-3.1.8-8.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>7.5</BaseScore>
        <Vector>AV:N/AC:L/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-10192.html</URL>
        <Description>CVE-2016-10192</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1022922</URL>
        <Description>SUSE Bug 1022922</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="3">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">The che_configure function in libavcodec/aacdec_template.c in FFmpeg before 3.2.1 allows remote attackers to cause a denial of service (allocation of huge memory, and being killed by the OS) via a crafted MOV file.</Note>
    </Notes>
    <CVE>CVE-2016-9561</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Package Hub 12 SP2:ffmpeg-3.1.8-8.1</ProductID>
        <ProductID>SUSE Package Hub 12 SP2:libavcodec-devel-3.1.8-8.1</ProductID>
        <ProductID>SUSE Package Hub 12 SP2:libavcodec57-3.1.8-8.1</ProductID>
        <ProductID>SUSE Package Hub 12 SP2:libavdevice-devel-3.1.8-8.1</ProductID>
        <ProductID>SUSE Package Hub 12 SP2:libavdevice57-3.1.8-8.1</ProductID>
        <ProductID>SUSE Package Hub 12 SP2:libavfilter-devel-3.1.8-8.1</ProductID>
        <ProductID>SUSE Package Hub 12 SP2:libavfilter6-3.1.8-8.1</ProductID>
        <ProductID>SUSE Package Hub 12 SP2:libavformat-devel-3.1.8-8.1</ProductID>
        <ProductID>SUSE Package Hub 12 SP2:libavformat57-3.1.8-8.1</ProductID>
        <ProductID>SUSE Package Hub 12 SP2:libavresample-devel-3.1.8-8.1</ProductID>
        <ProductID>SUSE Package Hub 12 SP2:libavresample3-3.1.8-8.1</ProductID>
        <ProductID>SUSE Package Hub 12 SP2:libavutil-devel-3.1.8-8.1</ProductID>
        <ProductID>SUSE Package Hub 12 SP2:libavutil55-3.1.8-8.1</ProductID>
        <ProductID>SUSE Package Hub 12 SP2:libpostproc-devel-3.1.8-8.1</ProductID>
        <ProductID>SUSE Package Hub 12 SP2:libpostproc54-3.1.8-8.1</ProductID>
        <ProductID>SUSE Package Hub 12 SP2:libswresample-devel-3.1.8-8.1</ProductID>
        <ProductID>SUSE Package Hub 12 SP2:libswresample2-3.1.8-8.1</ProductID>
        <ProductID>SUSE Package Hub 12 SP2:libswscale-devel-3.1.8-8.1</ProductID>
        <ProductID>SUSE Package Hub 12 SP2:libswscale4-3.1.8-8.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>4.3</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:N/I:N/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-9561.html</URL>
        <Description>CVE-2016-9561</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1015120</URL>
        <Description>SUSE Bug 1015120</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="4">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">FFmpeg in Google Chrome prior to 56.0.2924.76 for Linux, Windows and Mac, failed to perform proper bounds checking, which allowed a remote attacker to potentially exploit heap corruption via a crafted video file.</Note>
    </Notes>
    <CVE>CVE-2017-5024</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Package Hub 12 SP2:ffmpeg-3.1.8-8.1</ProductID>
        <ProductID>SUSE Package Hub 12 SP2:libavcodec-devel-3.1.8-8.1</ProductID>
        <ProductID>SUSE Package Hub 12 SP2:libavcodec57-3.1.8-8.1</ProductID>
        <ProductID>SUSE Package Hub 12 SP2:libavdevice-devel-3.1.8-8.1</ProductID>
        <ProductID>SUSE Package Hub 12 SP2:libavdevice57-3.1.8-8.1</ProductID>
        <ProductID>SUSE Package Hub 12 SP2:libavfilter-devel-3.1.8-8.1</ProductID>
        <ProductID>SUSE Package Hub 12 SP2:libavfilter6-3.1.8-8.1</ProductID>
        <ProductID>SUSE Package Hub 12 SP2:libavformat-devel-3.1.8-8.1</ProductID>
        <ProductID>SUSE Package Hub 12 SP2:libavformat57-3.1.8-8.1</ProductID>
        <ProductID>SUSE Package Hub 12 SP2:libavresample-devel-3.1.8-8.1</ProductID>
        <ProductID>SUSE Package Hub 12 SP2:libavresample3-3.1.8-8.1</ProductID>
        <ProductID>SUSE Package Hub 12 SP2:libavutil-devel-3.1.8-8.1</ProductID>
        <ProductID>SUSE Package Hub 12 SP2:libavutil55-3.1.8-8.1</ProductID>
        <ProductID>SUSE Package Hub 12 SP2:libpostproc-devel-3.1.8-8.1</ProductID>
        <ProductID>SUSE Package Hub 12 SP2:libpostproc54-3.1.8-8.1</ProductID>
        <ProductID>SUSE Package Hub 12 SP2:libswresample-devel-3.1.8-8.1</ProductID>
        <ProductID>SUSE Package Hub 12 SP2:libswresample2-3.1.8-8.1</ProductID>
        <ProductID>SUSE Package Hub 12 SP2:libswscale-devel-3.1.8-8.1</ProductID>
        <ProductID>SUSE Package Hub 12 SP2:libswscale4-3.1.8-8.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>4.3</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:N/I:N/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2017-5024.html</URL>
        <Description>CVE-2017-5024</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1022049</URL>
        <Description>SUSE Bug 1022049</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="5">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">FFmpeg in Google Chrome prior to 56.0.2924.76 for Linux, Windows and Mac, failed to perform proper bounds checking, which allowed a remote attacker to potentially exploit heap corruption via a crafted video file.</Note>
    </Notes>
    <CVE>CVE-2017-5025</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Package Hub 12 SP2:ffmpeg-3.1.8-8.1</ProductID>
        <ProductID>SUSE Package Hub 12 SP2:libavcodec-devel-3.1.8-8.1</ProductID>
        <ProductID>SUSE Package Hub 12 SP2:libavcodec57-3.1.8-8.1</ProductID>
        <ProductID>SUSE Package Hub 12 SP2:libavdevice-devel-3.1.8-8.1</ProductID>
        <ProductID>SUSE Package Hub 12 SP2:libavdevice57-3.1.8-8.1</ProductID>
        <ProductID>SUSE Package Hub 12 SP2:libavfilter-devel-3.1.8-8.1</ProductID>
        <ProductID>SUSE Package Hub 12 SP2:libavfilter6-3.1.8-8.1</ProductID>
        <ProductID>SUSE Package Hub 12 SP2:libavformat-devel-3.1.8-8.1</ProductID>
        <ProductID>SUSE Package Hub 12 SP2:libavformat57-3.1.8-8.1</ProductID>
        <ProductID>SUSE Package Hub 12 SP2:libavresample-devel-3.1.8-8.1</ProductID>
        <ProductID>SUSE Package Hub 12 SP2:libavresample3-3.1.8-8.1</ProductID>
        <ProductID>SUSE Package Hub 12 SP2:libavutil-devel-3.1.8-8.1</ProductID>
        <ProductID>SUSE Package Hub 12 SP2:libavutil55-3.1.8-8.1</ProductID>
        <ProductID>SUSE Package Hub 12 SP2:libpostproc-devel-3.1.8-8.1</ProductID>
        <ProductID>SUSE Package Hub 12 SP2:libpostproc54-3.1.8-8.1</ProductID>
        <ProductID>SUSE Package Hub 12 SP2:libswresample-devel-3.1.8-8.1</ProductID>
        <ProductID>SUSE Package Hub 12 SP2:libswresample2-3.1.8-8.1</ProductID>
        <ProductID>SUSE Package Hub 12 SP2:libswscale-devel-3.1.8-8.1</ProductID>
        <ProductID>SUSE Package Hub 12 SP2:libswscale4-3.1.8-8.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>4.3</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:N/I:N/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2017-5025.html</URL>
        <Description>CVE-2017-5025</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1022049</URL>
        <Description>SUSE Bug 1022049</Description>
      </Reference>
    </References>
  </Vulnerability>
</cvrfdoc>
