Multiple vulnerabilities have been found in libav, the worst of which may allow execution of arbitrary code.
|Package||media-video/libav on all architectures|
|Affected versions||< 11.8|
|Unaffected versions||>= 11.8|
Libav is a complete solution to record, convert and stream audio and video.
Multiple vulnerabilities have been discovered in libav. Please review the CVE identifiers referenced below for details.
A remote attacker could entice a user to open a specially crafted media file in an application linked against libav, possibly resulting in execution of arbitrary code with the privileges of the application, a Denial of Service condition or access the content of arbitrary local files.
There is no known workaround at this time.
All libav users should upgrade to the latest version:
# emerge --sync # emerge --ask --oneshot --verbose ">=media-video/libav-11.8"