Four Ubuntu distributions have been affected by this problem

Nov 6, 2013 12:47 GMT  ·  By

Canonical published some details about a Libav vulnerability in its Ubuntu 13.10, Ubuntu 13.04, Ubuntu 12.10, and Ubuntu 12.04 LTS operating systems.

According to the company, Libav could have been made to crash or to run programs as the user's login, if it opened a specially crafted file.

It has been discovered that Libav incorrectly handled certain malformed media files. If a user was tricked into opening a crafted media file, an attacker could have caused a denial of service via application crash, or could have possibly executed arbitrary code with the privileges of the user invoking the program.

For a more detailed description of the security problems, you can see Canonical's security notification.

The security flaws can be fixed if you upgrade your system(s) to the latest libavformat53 and libavcodec53 packages specific to each distribution. To apply the update, run the Update Manager application.

In general, a standard system update will make all the necessary changes and a restart is not required.