Index: security/vuxml/vuln.xml =================================================================== --- security/vuxml/vuln.xml (revision 454031) +++ security/vuxml/vuln.xml (working copy) @@ -58,6 +58,35 @@ * Do not forget port variants (linux-f10-libxml2, libxml2, etc.) --> + + ffmpeg -- double free vulnerability + + + ffmpeg + 3.3.4_1,1 + + + + +

MITRE reports:

+
+

Double free vulnerability in FFmpeg 3.3.4 and earlier allows + remote attackers to cause a denial of service via a crafted + AVI file.

+
+ +
+ + https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-15186 + http://ffmpeg.org/security.html + CVE-2017-15186 + + + 2017-10-09 + 2017-11-12 + +
+ roundcube -- file disclosure vulnerability