<?xml version="1.0" encoding="UTF-8"?>
<cvrfdoc xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:cpe="http://cpe.mitre.org/language/2.0" xmlns:cvrf="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/cvrf" xmlns:cvrf-common="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/common" xmlns:cvssv2="http://scap.nist.gov/schema/cvss-v2/1.0" xmlns:cvssv3="https://www.first.org/cvss/cvss-v3.0.xsd" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:ns0="http://purl.org/dc/elements/1.1/" xmlns:prod="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/prod" xmlns:scap-core="http://scap.nist.gov/schema/scap-core/1.0" xmlns:sch="http://purl.oclc.org/dsdl/schematron" xmlns:vuln="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/vuln" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/cvrf">
  <DocumentTitle xml:lang="en">CVE-2018-1999015</DocumentTitle>
  <DocumentType>SUSE CVE</DocumentType>
  <DocumentPublisher Type="Vendor">
    <ContactDetails>security@suse.de</ContactDetails>
    <IssuingAuthority>SUSE Security Team</IssuingAuthority>
  </DocumentPublisher>
  <DocumentTracking>
    <Identification>
      <ID>SUSE CVE-2018-1999015</ID>
    </Identification>
    <Status>Interim</Status>
    <Version>1</Version>
    <RevisionHistory>
      <Revision>
        <Number>17</Number>
        <Date>2025-02-17T02:26:18Z</Date>
        <Description>current</Description>
      </Revision>
    </RevisionHistory>
    <InitialReleaseDate>2021-05-30T14:20:56Z</InitialReleaseDate>
    <CurrentReleaseDate>2025-02-17T02:26:18Z</CurrentReleaseDate>
    <Generator>
      <Engine>cve-database/bin/generate-cvrf-cve.pl</Engine>
      <Date>2020-12-27T01:00:00Z</Date>
    </Generator>
  </DocumentTracking>
  <DocumentNotes>
    <Note Title="CVE" Type="Summary" Ordinal="1" xml:lang="en">CVE-2018-1999015</Note>
    <Note Title="Mitre CVE Description" Type="Description" Ordinal="2" xml:lang="en">FFmpeg before commit 5aba5b89d0b1d73164d3b81764828bb8b20ff32a contains an out of array read vulnerability in ASF_F format demuxer that can result in heap memory reading. This attack appear to be exploitable via specially crafted ASF file that has to provided as input. This vulnerability appears to have been fixed in 5aba5b89d0b1d73164d3b81764828bb8b20ff32a and later.</Note>
    <Note Title="Terms of Use" Type="Legal Disclaimer" Ordinal="4" xml:lang="en">The CVRF data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).</Note>
  </DocumentNotes>
  <DocumentReferences>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/security/rating/</URL>
      <Description>SUSE Security Ratings</Description>
    </Reference>
  </DocumentReferences>
  <ProductTree xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/prod">
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Desktop 15">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Module for Desktop Applications 15">
        <FullProductName ProductID="SUSE Linux Enterprise Module for Desktop Applications 15" CPE="cpe:/o:suse:sle-module-desktop-applications:15">SUSE Linux Enterprise Module for Desktop Applications 15</FullProductName>
      </Branch>
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Workstation Extension 15">
        <FullProductName ProductID="SUSE Linux Enterprise Workstation Extension 15" CPE="cpe:/o:suse:sle-we:15">SUSE Linux Enterprise Workstation Extension 15</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise High Performance Computing 15">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Module for Desktop Applications 15">
        <FullProductName ProductID="SUSE Linux Enterprise Module for Desktop Applications 15" CPE="cpe:/o:suse:sle-module-desktop-applications:15">SUSE Linux Enterprise Module for Desktop Applications 15</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS">
        <FullProductName ProductID="SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS" CPE="cpe:/o:suse:sle_hpc-espos:15:sp1">SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Module for Package Hub 15">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Module for Package Hub 15">
        <FullProductName ProductID="SUSE Linux Enterprise Module for Package Hub 15" CPE="cpe:/o:suse:packagehub:15">SUSE Linux Enterprise Module for Package Hub 15</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Module for Package Hub 15 SP1">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Module for Package Hub 15 SP1">
        <FullProductName ProductID="SUSE Linux Enterprise Module for Package Hub 15 SP1" CPE="cpe:/o:suse:packagehub:15:sp1">SUSE Linux Enterprise Module for Package Hub 15 SP1</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Server 15">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Module for Desktop Applications 15">
        <FullProductName ProductID="SUSE Linux Enterprise Module for Desktop Applications 15" CPE="cpe:/o:suse:sle-module-desktop-applications:15">SUSE Linux Enterprise Module for Desktop Applications 15</FullProductName>
      </Branch>
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Workstation Extension 15">
        <FullProductName ProductID="SUSE Linux Enterprise Workstation Extension 15" CPE="cpe:/o:suse:sle-we:15">SUSE Linux Enterprise Workstation Extension 15</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Server for SAP Applications 15">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Module for Desktop Applications 15">
        <FullProductName ProductID="SUSE Linux Enterprise Module for Desktop Applications 15" CPE="cpe:/o:suse:sle-module-desktop-applications:15">SUSE Linux Enterprise Module for Desktop Applications 15</FullProductName>
      </Branch>
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Workstation Extension 15">
        <FullProductName ProductID="SUSE Linux Enterprise Workstation Extension 15" CPE="cpe:/o:suse:sle-we:15">SUSE Linux Enterprise Workstation Extension 15</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Version" Name="ffmpeg">
      <FullProductName ProductID="ffmpeg" CPE="cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*">ffmpeg</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libavcodec-devel">
      <FullProductName ProductID="libavcodec-devel">libavcodec-devel</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libavcodec57">
      <FullProductName ProductID="libavcodec57">libavcodec57</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libavcodec57-32bit">
      <FullProductName ProductID="libavcodec57-32bit">libavcodec57-32bit</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libavdevice-devel">
      <FullProductName ProductID="libavdevice-devel">libavdevice-devel</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libavdevice57">
      <FullProductName ProductID="libavdevice57">libavdevice57</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libavdevice57-32bit">
      <FullProductName ProductID="libavdevice57-32bit">libavdevice57-32bit</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libavfilter-devel">
      <FullProductName ProductID="libavfilter-devel">libavfilter-devel</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libavfilter6">
      <FullProductName ProductID="libavfilter6">libavfilter6</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libavfilter6-32bit">
      <FullProductName ProductID="libavfilter6-32bit">libavfilter6-32bit</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libavformat-devel">
      <FullProductName ProductID="libavformat-devel">libavformat-devel</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libavformat57">
      <FullProductName ProductID="libavformat57">libavformat57</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libavformat57-32bit">
      <FullProductName ProductID="libavformat57-32bit">libavformat57-32bit</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libavresample-devel">
      <FullProductName ProductID="libavresample-devel">libavresample-devel</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libavresample3">
      <FullProductName ProductID="libavresample3">libavresample3</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libavresample3-32bit">
      <FullProductName ProductID="libavresample3-32bit">libavresample3-32bit</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libavutil-devel">
      <FullProductName ProductID="libavutil-devel">libavutil-devel</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libavutil55">
      <FullProductName ProductID="libavutil55">libavutil55</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libavutil55-32bit">
      <FullProductName ProductID="libavutil55-32bit">libavutil55-32bit</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libpostproc-devel">
      <FullProductName ProductID="libpostproc-devel">libpostproc-devel</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libpostproc54">
      <FullProductName ProductID="libpostproc54">libpostproc54</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libpostproc54-32bit">
      <FullProductName ProductID="libpostproc54-32bit">libpostproc54-32bit</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libswresample-devel">
      <FullProductName ProductID="libswresample-devel">libswresample-devel</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libswresample2">
      <FullProductName ProductID="libswresample2">libswresample2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libswresample2-32bit">
      <FullProductName ProductID="libswresample2-32bit">libswresample2-32bit</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libswscale-devel">
      <FullProductName ProductID="libswscale-devel">libswscale-devel</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libswscale4">
      <FullProductName ProductID="libswscale4">libswscale4</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libswscale4-32bit">
      <FullProductName ProductID="libswscale4-32bit">libswscale4-32bit</FullProductName>
    </Branch>
    <Relationship ProductReference="libavcodec-devel" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS">
      <FullProductName ProductID="SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS:libavcodec-devel">libavcodec-devel as a component of SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS</FullProductName>
    </Relationship>
    <Relationship ProductReference="libavcodec57" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS">
      <FullProductName ProductID="SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS:libavcodec57">libavcodec57 as a component of SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS</FullProductName>
    </Relationship>
    <Relationship ProductReference="libavcodec57-32bit" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS">
      <FullProductName ProductID="SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS:libavcodec57-32bit">libavcodec57-32bit as a component of SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS</FullProductName>
    </Relationship>
    <Relationship ProductReference="libavdevice-devel" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS">
      <FullProductName ProductID="SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS:libavdevice-devel">libavdevice-devel as a component of SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS</FullProductName>
    </Relationship>
    <Relationship ProductReference="libavdevice57" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS">
      <FullProductName ProductID="SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS:libavdevice57">libavdevice57 as a component of SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS</FullProductName>
    </Relationship>
    <Relationship ProductReference="libavdevice57-32bit" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS">
      <FullProductName ProductID="SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS:libavdevice57-32bit">libavdevice57-32bit as a component of SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS</FullProductName>
    </Relationship>
    <Relationship ProductReference="libavfilter-devel" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS">
      <FullProductName ProductID="SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS:libavfilter-devel">libavfilter-devel as a component of SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS</FullProductName>
    </Relationship>
    <Relationship ProductReference="libavfilter6" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS">
      <FullProductName ProductID="SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS:libavfilter6">libavfilter6 as a component of SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS</FullProductName>
    </Relationship>
    <Relationship ProductReference="libavfilter6-32bit" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS">
      <FullProductName ProductID="SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS:libavfilter6-32bit">libavfilter6-32bit as a component of SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS</FullProductName>
    </Relationship>
    <Relationship ProductReference="libavformat-devel" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS">
      <FullProductName ProductID="SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS:libavformat-devel">libavformat-devel as a component of SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS</FullProductName>
    </Relationship>
    <Relationship ProductReference="libavformat57" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS">
      <FullProductName ProductID="SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS:libavformat57">libavformat57 as a component of SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS</FullProductName>
    </Relationship>
    <Relationship ProductReference="libavformat57-32bit" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS">
      <FullProductName ProductID="SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS:libavformat57-32bit">libavformat57-32bit as a component of SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS</FullProductName>
    </Relationship>
    <Relationship ProductReference="libavresample-devel" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS">
      <FullProductName ProductID="SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS:libavresample-devel">libavresample-devel as a component of SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS</FullProductName>
    </Relationship>
    <Relationship ProductReference="libavresample3" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS">
      <FullProductName ProductID="SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS:libavresample3">libavresample3 as a component of SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS</FullProductName>
    </Relationship>
    <Relationship ProductReference="libavresample3-32bit" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS">
      <FullProductName ProductID="SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS:libavresample3-32bit">libavresample3-32bit as a component of SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS</FullProductName>
    </Relationship>
    <Relationship ProductReference="libavutil-devel" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS">
      <FullProductName ProductID="SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS:libavutil-devel">libavutil-devel as a component of SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS</FullProductName>
    </Relationship>
    <Relationship ProductReference="libavutil55" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS">
      <FullProductName ProductID="SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS:libavutil55">libavutil55 as a component of SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS</FullProductName>
    </Relationship>
    <Relationship ProductReference="libavutil55-32bit" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS">
      <FullProductName ProductID="SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS:libavutil55-32bit">libavutil55-32bit as a component of SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS</FullProductName>
    </Relationship>
    <Relationship ProductReference="libpostproc-devel" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS">
      <FullProductName ProductID="SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS:libpostproc-devel">libpostproc-devel as a component of SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS</FullProductName>
    </Relationship>
    <Relationship ProductReference="libpostproc54" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS">
      <FullProductName ProductID="SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS:libpostproc54">libpostproc54 as a component of SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS</FullProductName>
    </Relationship>
    <Relationship ProductReference="libpostproc54-32bit" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS">
      <FullProductName ProductID="SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS:libpostproc54-32bit">libpostproc54-32bit as a component of SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS</FullProductName>
    </Relationship>
    <Relationship ProductReference="libswresample-devel" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS">
      <FullProductName ProductID="SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS:libswresample-devel">libswresample-devel as a component of SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS</FullProductName>
    </Relationship>
    <Relationship ProductReference="libswresample2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS">
      <FullProductName ProductID="SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS:libswresample2">libswresample2 as a component of SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS</FullProductName>
    </Relationship>
    <Relationship ProductReference="libswresample2-32bit" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS">
      <FullProductName ProductID="SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS:libswresample2-32bit">libswresample2-32bit as a component of SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS</FullProductName>
    </Relationship>
    <Relationship ProductReference="libswscale-devel" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS">
      <FullProductName ProductID="SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS:libswscale-devel">libswscale-devel as a component of SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS</FullProductName>
    </Relationship>
    <Relationship ProductReference="libswscale4" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS">
      <FullProductName ProductID="SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS:libswscale4">libswscale4 as a component of SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS</FullProductName>
    </Relationship>
    <Relationship ProductReference="libswscale4-32bit" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS">
      <FullProductName ProductID="SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS:libswscale4-32bit">libswscale4-32bit as a component of SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS</FullProductName>
    </Relationship>
    <Relationship ProductReference="ffmpeg" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS">
      <FullProductName ProductID="SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS:ffmpeg">ffmpeg as a component of SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS</FullProductName>
    </Relationship>
    <Relationship ProductReference="libavcodec57" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Desktop Applications 15">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Desktop Applications 15:libavcodec57">libavcodec57 as a component of SUSE Linux Enterprise Module for Desktop Applications 15</FullProductName>
    </Relationship>
    <Relationship ProductReference="libavutil-devel" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Desktop Applications 15">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Desktop Applications 15:libavutil-devel">libavutil-devel as a component of SUSE Linux Enterprise Module for Desktop Applications 15</FullProductName>
    </Relationship>
    <Relationship ProductReference="libavutil55" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Desktop Applications 15">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Desktop Applications 15:libavutil55">libavutil55 as a component of SUSE Linux Enterprise Module for Desktop Applications 15</FullProductName>
    </Relationship>
    <Relationship ProductReference="libpostproc-devel" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Desktop Applications 15">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Desktop Applications 15:libpostproc-devel">libpostproc-devel as a component of SUSE Linux Enterprise Module for Desktop Applications 15</FullProductName>
    </Relationship>
    <Relationship ProductReference="libpostproc54" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Desktop Applications 15">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Desktop Applications 15:libpostproc54">libpostproc54 as a component of SUSE Linux Enterprise Module for Desktop Applications 15</FullProductName>
    </Relationship>
    <Relationship ProductReference="libswresample-devel" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Desktop Applications 15">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Desktop Applications 15:libswresample-devel">libswresample-devel as a component of SUSE Linux Enterprise Module for Desktop Applications 15</FullProductName>
    </Relationship>
    <Relationship ProductReference="libswresample2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Desktop Applications 15">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Desktop Applications 15:libswresample2">libswresample2 as a component of SUSE Linux Enterprise Module for Desktop Applications 15</FullProductName>
    </Relationship>
    <Relationship ProductReference="libswscale-devel" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Desktop Applications 15">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Desktop Applications 15:libswscale-devel">libswscale-devel as a component of SUSE Linux Enterprise Module for Desktop Applications 15</FullProductName>
    </Relationship>
    <Relationship ProductReference="libswscale4" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Desktop Applications 15">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Desktop Applications 15:libswscale4">libswscale4 as a component of SUSE Linux Enterprise Module for Desktop Applications 15</FullProductName>
    </Relationship>
    <Relationship ProductReference="ffmpeg" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Desktop Applications 15">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Desktop Applications 15:ffmpeg">ffmpeg as a component of SUSE Linux Enterprise Module for Desktop Applications 15</FullProductName>
    </Relationship>
    <Relationship ProductReference="ffmpeg" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Package Hub 15">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Package Hub 15:ffmpeg">ffmpeg as a component of SUSE Linux Enterprise Module for Package Hub 15</FullProductName>
    </Relationship>
    <Relationship ProductReference="libavdevice57" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Package Hub 15">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Package Hub 15:libavdevice57">libavdevice57 as a component of SUSE Linux Enterprise Module for Package Hub 15</FullProductName>
    </Relationship>
    <Relationship ProductReference="libavfilter6" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Package Hub 15">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Package Hub 15:libavfilter6">libavfilter6 as a component of SUSE Linux Enterprise Module for Package Hub 15</FullProductName>
    </Relationship>
    <Relationship ProductReference="ffmpeg" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Package Hub 15 SP1">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Package Hub 15 SP1:ffmpeg">ffmpeg as a component of SUSE Linux Enterprise Module for Package Hub 15 SP1</FullProductName>
    </Relationship>
    <Relationship ProductReference="libavdevice57" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Package Hub 15 SP1">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Package Hub 15 SP1:libavdevice57">libavdevice57 as a component of SUSE Linux Enterprise Module for Package Hub 15 SP1</FullProductName>
    </Relationship>
    <Relationship ProductReference="libavfilter6" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Package Hub 15 SP1">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Package Hub 15 SP1:libavfilter6">libavfilter6 as a component of SUSE Linux Enterprise Module for Package Hub 15 SP1</FullProductName>
    </Relationship>
    <Relationship ProductReference="libavcodec-devel" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Workstation Extension 15">
      <FullProductName ProductID="SUSE Linux Enterprise Workstation Extension 15:libavcodec-devel">libavcodec-devel as a component of SUSE Linux Enterprise Workstation Extension 15</FullProductName>
    </Relationship>
    <Relationship ProductReference="libavformat-devel" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Workstation Extension 15">
      <FullProductName ProductID="SUSE Linux Enterprise Workstation Extension 15:libavformat-devel">libavformat-devel as a component of SUSE Linux Enterprise Workstation Extension 15</FullProductName>
    </Relationship>
    <Relationship ProductReference="libavformat57" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Workstation Extension 15">
      <FullProductName ProductID="SUSE Linux Enterprise Workstation Extension 15:libavformat57">libavformat57 as a component of SUSE Linux Enterprise Workstation Extension 15</FullProductName>
    </Relationship>
    <Relationship ProductReference="libavresample-devel" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Workstation Extension 15">
      <FullProductName ProductID="SUSE Linux Enterprise Workstation Extension 15:libavresample-devel">libavresample-devel as a component of SUSE Linux Enterprise Workstation Extension 15</FullProductName>
    </Relationship>
    <Relationship ProductReference="libavresample3" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Workstation Extension 15">
      <FullProductName ProductID="SUSE Linux Enterprise Workstation Extension 15:libavresample3">libavresample3 as a component of SUSE Linux Enterprise Workstation Extension 15</FullProductName>
    </Relationship>
    <Relationship ProductReference="ffmpeg" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Workstation Extension 15">
      <FullProductName ProductID="SUSE Linux Enterprise Workstation Extension 15:ffmpeg">ffmpeg as a component of SUSE Linux Enterprise Workstation Extension 15</FullProductName>
    </Relationship>
  </ProductTree>
  <Vulnerability xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/vuln" Ordinal="1">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">FFmpeg before commit 5aba5b89d0b1d73164d3b81764828bb8b20ff32a contains an out of array read vulnerability in ASF_F format demuxer that can result in heap memory reading. This attack appear to be exploitable via specially crafted ASF file that has to provided as input. This vulnerability appears to have been fixed in 5aba5b89d0b1d73164d3b81764828bb8b20ff32a and later.</Note>
    </Notes>
    <CVE>CVE-2018-1999015</CVE>
    <ProductStatuses>
      <Status Type="Known Not Affected">
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS:ffmpeg</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS:libavcodec-devel</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS:libavcodec57</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS:libavcodec57-32bit</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS:libavdevice-devel</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS:libavdevice57</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS:libavdevice57-32bit</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS:libavfilter-devel</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS:libavfilter6</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS:libavfilter6-32bit</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS:libavformat-devel</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS:libavformat57</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS:libavformat57-32bit</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS:libavresample-devel</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS:libavresample3</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS:libavresample3-32bit</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS:libavutil-devel</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS:libavutil55</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS:libavutil55-32bit</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS:libpostproc-devel</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS:libpostproc54</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS:libpostproc54-32bit</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS:libswresample-devel</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS:libswresample2</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS:libswresample2-32bit</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS:libswscale-devel</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS:libswscale4</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS:libswscale4-32bit</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Desktop Applications 15:ffmpeg</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Desktop Applications 15:libavcodec57</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Desktop Applications 15:libavutil-devel</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Desktop Applications 15:libavutil55</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Desktop Applications 15:libpostproc-devel</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Desktop Applications 15:libpostproc54</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Desktop Applications 15:libswresample-devel</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Desktop Applications 15:libswresample2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Desktop Applications 15:libswscale-devel</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Desktop Applications 15:libswscale4</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Package Hub 15 SP1:ffmpeg</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Package Hub 15 SP1:libavdevice57</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Package Hub 15 SP1:libavfilter6</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Package Hub 15:ffmpeg</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Package Hub 15:libavdevice57</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Package Hub 15:libavfilter6</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 15:ffmpeg</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 15:libavcodec-devel</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 15:libavformat-devel</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 15:libavformat57</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 15:libavresample-devel</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 15:libavresample3</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSetV2>
        <BaseScoreV2>4.3</BaseScoreV2>
        <VectorV2>AV:N/AC:M/Au:N/C:P/I:N/A:N</VectorV2>
      </ScoreSetV2>
      <ScoreSetV3>
        <BaseScoreV3>4.4</BaseScoreV3>
        <VectorV3>CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L</VectorV3>
      </ScoreSetV3>
    </CVSSScoreSets>
  </Vulnerability>
</cvrfdoc>
