<?xml version="1.0" encoding="UTF-8"?>
<cvrfdoc xmlns="http://www.icasi.org/CVRF/schema/cvrf/1.1" xmlns:cvrf="http://www.icasi.org/CVRF/schema/cvrf/1.1">
  <DocumentTitle xml:lang="en">ffmpeg-3.2.2-1.1 on GA media</DocumentTitle>
  <DocumentType>SUSE Patch</DocumentType>
  <DocumentPublisher Type="Vendor">
    <ContactDetails>security@suse.de</ContactDetails>
    <IssuingAuthority>SUSE Security Team</IssuingAuthority>
  </DocumentPublisher>
  <DocumentTracking>
    <Identification>
      <ID>openSUSE-SU-2024:10243-1</ID>
    </Identification>
    <Status>Final</Status>
    <Version>1</Version>
    <RevisionHistory>
      <Revision>
        <Number>1</Number>
        <Date>2024-06-15T00:00:00Z</Date>
        <Description>current</Description>
      </Revision>
    </RevisionHistory>
    <InitialReleaseDate>2024-06-15T00:00:00Z</InitialReleaseDate>
    <CurrentReleaseDate>2024-06-15T00:00:00Z</CurrentReleaseDate>
    <Generator>
      <Engine>cve-database/bin/generate-cvrf.pl</Engine>
      <Date>2017-02-24T01:00:00Z</Date>
    </Generator>
  </DocumentTracking>
  <DocumentNotes>
    <Note Title="Topic" Type="Summary" Ordinal="1" xml:lang="en">ffmpeg-3.2.2-1.1 on GA media</Note>
    <Note Title="Details" Type="General" Ordinal="2" xml:lang="en">These are all security issues fixed in the ffmpeg-3.2.2-1.1 package on the GA media of openSUSE Tumbleweed.</Note>
    <Note Title="Terms of Use" Type="Legal Disclaimer" Ordinal="3" xml:lang="en">The CVRF data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).</Note>
    <Note Title="Patchnames" Type="Details" Ordinal="4" xml:lang="en">openSUSE-Tumbleweed-2024-10243</Note>
  </DocumentNotes>
  <DocumentDistribution xml:lang="en">Copyright SUSE LLC under the Creative Commons License 4.0 with Attribution (CC-BY-4.0)</DocumentDistribution>
  <DocumentReferences>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/security/rating/</URL>
      <Description>SUSE Security Ratings</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2015-8216/</URL>
      <Description>SUSE CVE CVE-2015-8216 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2015-8217/</URL>
      <Description>SUSE CVE CVE-2015-8217 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2015-8218/</URL>
      <Description>SUSE CVE CVE-2015-8218 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2015-8219/</URL>
      <Description>SUSE CVE CVE-2015-8219 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2015-8363/</URL>
      <Description>SUSE CVE CVE-2015-8363 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2015-8364/</URL>
      <Description>SUSE CVE CVE-2015-8364 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2015-8365/</URL>
      <Description>SUSE CVE CVE-2015-8365 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2015-8661/</URL>
      <Description>SUSE CVE CVE-2015-8661 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2015-8662/</URL>
      <Description>SUSE CVE CVE-2015-8662 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2015-8663/</URL>
      <Description>SUSE CVE CVE-2015-8663 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2016-1897/</URL>
      <Description>SUSE CVE CVE-2016-1897 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2016-1898/</URL>
      <Description>SUSE CVE CVE-2016-1898 page</Description>
    </Reference>
  </DocumentReferences>
  <ProductTree xmlns="http://www.icasi.org/CVRF/schema/prod/1.1">
    <Branch Type="Product Family" Name="openSUSE Tumbleweed">
      <Branch Type="Product Name" Name="openSUSE Tumbleweed">
        <FullProductName ProductID="openSUSE Tumbleweed" CPE="cpe:/o:opensuse:tumbleweed">openSUSE Tumbleweed</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Version" Name="ffmpeg-3.2.2-1.1">
      <FullProductName ProductID="ffmpeg-3.2.2-1.1">ffmpeg-3.2.2-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="ffmpeg2-devel-2.8.8-3.1">
      <FullProductName ProductID="ffmpeg2-devel-2.8.8-3.1">ffmpeg2-devel-2.8.8-3.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libavcodec-devel-3.2.2-1.1">
      <FullProductName ProductID="libavcodec-devel-3.2.2-1.1">libavcodec-devel-3.2.2-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libavcodec56-2.8.8-3.1">
      <FullProductName ProductID="libavcodec56-2.8.8-3.1">libavcodec56-2.8.8-3.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libavcodec56-32bit-2.8.8-3.1">
      <FullProductName ProductID="libavcodec56-32bit-2.8.8-3.1">libavcodec56-32bit-2.8.8-3.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libavcodec57-3.2.2-1.1">
      <FullProductName ProductID="libavcodec57-3.2.2-1.1">libavcodec57-3.2.2-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libavcodec57-32bit-3.2.2-1.1">
      <FullProductName ProductID="libavcodec57-32bit-3.2.2-1.1">libavcodec57-32bit-3.2.2-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libavdevice-devel-3.2.2-1.1">
      <FullProductName ProductID="libavdevice-devel-3.2.2-1.1">libavdevice-devel-3.2.2-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libavdevice56-2.8.8-3.1">
      <FullProductName ProductID="libavdevice56-2.8.8-3.1">libavdevice56-2.8.8-3.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libavdevice56-32bit-2.8.8-3.1">
      <FullProductName ProductID="libavdevice56-32bit-2.8.8-3.1">libavdevice56-32bit-2.8.8-3.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libavdevice57-3.2.2-1.1">
      <FullProductName ProductID="libavdevice57-3.2.2-1.1">libavdevice57-3.2.2-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libavdevice57-32bit-3.2.2-1.1">
      <FullProductName ProductID="libavdevice57-32bit-3.2.2-1.1">libavdevice57-32bit-3.2.2-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libavfilter-devel-3.2.2-1.1">
      <FullProductName ProductID="libavfilter-devel-3.2.2-1.1">libavfilter-devel-3.2.2-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libavfilter5-2.8.8-3.1">
      <FullProductName ProductID="libavfilter5-2.8.8-3.1">libavfilter5-2.8.8-3.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libavfilter5-32bit-2.8.8-3.1">
      <FullProductName ProductID="libavfilter5-32bit-2.8.8-3.1">libavfilter5-32bit-2.8.8-3.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libavfilter6-3.2.2-1.1">
      <FullProductName ProductID="libavfilter6-3.2.2-1.1">libavfilter6-3.2.2-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libavfilter6-32bit-3.2.2-1.1">
      <FullProductName ProductID="libavfilter6-32bit-3.2.2-1.1">libavfilter6-32bit-3.2.2-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libavformat-devel-3.2.2-1.1">
      <FullProductName ProductID="libavformat-devel-3.2.2-1.1">libavformat-devel-3.2.2-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libavformat56-2.8.8-3.1">
      <FullProductName ProductID="libavformat56-2.8.8-3.1">libavformat56-2.8.8-3.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libavformat56-32bit-2.8.8-3.1">
      <FullProductName ProductID="libavformat56-32bit-2.8.8-3.1">libavformat56-32bit-2.8.8-3.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libavformat57-3.2.2-1.1">
      <FullProductName ProductID="libavformat57-3.2.2-1.1">libavformat57-3.2.2-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libavformat57-32bit-3.2.2-1.1">
      <FullProductName ProductID="libavformat57-32bit-3.2.2-1.1">libavformat57-32bit-3.2.2-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libavresample-devel-3.2.2-1.1">
      <FullProductName ProductID="libavresample-devel-3.2.2-1.1">libavresample-devel-3.2.2-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libavresample2-2.8.8-3.1">
      <FullProductName ProductID="libavresample2-2.8.8-3.1">libavresample2-2.8.8-3.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libavresample2-32bit-2.8.8-3.1">
      <FullProductName ProductID="libavresample2-32bit-2.8.8-3.1">libavresample2-32bit-2.8.8-3.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libavresample3-3.2.2-1.1">
      <FullProductName ProductID="libavresample3-3.2.2-1.1">libavresample3-3.2.2-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libavresample3-32bit-3.2.2-1.1">
      <FullProductName ProductID="libavresample3-32bit-3.2.2-1.1">libavresample3-32bit-3.2.2-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libavutil-devel-3.2.2-1.1">
      <FullProductName ProductID="libavutil-devel-3.2.2-1.1">libavutil-devel-3.2.2-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libavutil54-2.8.8-3.1">
      <FullProductName ProductID="libavutil54-2.8.8-3.1">libavutil54-2.8.8-3.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libavutil54-32bit-2.8.8-3.1">
      <FullProductName ProductID="libavutil54-32bit-2.8.8-3.1">libavutil54-32bit-2.8.8-3.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libavutil55-3.2.2-1.1">
      <FullProductName ProductID="libavutil55-3.2.2-1.1">libavutil55-3.2.2-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libavutil55-32bit-3.2.2-1.1">
      <FullProductName ProductID="libavutil55-32bit-3.2.2-1.1">libavutil55-32bit-3.2.2-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libpostproc-devel-3.2.2-1.1">
      <FullProductName ProductID="libpostproc-devel-3.2.2-1.1">libpostproc-devel-3.2.2-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libpostproc53-2.8.8-3.1">
      <FullProductName ProductID="libpostproc53-2.8.8-3.1">libpostproc53-2.8.8-3.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libpostproc53-32bit-2.8.8-3.1">
      <FullProductName ProductID="libpostproc53-32bit-2.8.8-3.1">libpostproc53-32bit-2.8.8-3.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libpostproc54-3.2.2-1.1">
      <FullProductName ProductID="libpostproc54-3.2.2-1.1">libpostproc54-3.2.2-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libpostproc54-32bit-3.2.2-1.1">
      <FullProductName ProductID="libpostproc54-32bit-3.2.2-1.1">libpostproc54-32bit-3.2.2-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libswresample-devel-3.2.2-1.1">
      <FullProductName ProductID="libswresample-devel-3.2.2-1.1">libswresample-devel-3.2.2-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libswresample1-2.8.8-3.1">
      <FullProductName ProductID="libswresample1-2.8.8-3.1">libswresample1-2.8.8-3.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libswresample1-32bit-2.8.8-3.1">
      <FullProductName ProductID="libswresample1-32bit-2.8.8-3.1">libswresample1-32bit-2.8.8-3.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libswresample2-3.2.2-1.1">
      <FullProductName ProductID="libswresample2-3.2.2-1.1">libswresample2-3.2.2-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libswresample2-32bit-3.2.2-1.1">
      <FullProductName ProductID="libswresample2-32bit-3.2.2-1.1">libswresample2-32bit-3.2.2-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libswscale-devel-3.2.2-1.1">
      <FullProductName ProductID="libswscale-devel-3.2.2-1.1">libswscale-devel-3.2.2-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libswscale3-2.8.8-3.1">
      <FullProductName ProductID="libswscale3-2.8.8-3.1">libswscale3-2.8.8-3.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libswscale3-32bit-2.8.8-3.1">
      <FullProductName ProductID="libswscale3-32bit-2.8.8-3.1">libswscale3-32bit-2.8.8-3.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libswscale4-3.2.2-1.1">
      <FullProductName ProductID="libswscale4-3.2.2-1.1">libswscale4-3.2.2-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libswscale4-32bit-3.2.2-1.1">
      <FullProductName ProductID="libswscale4-32bit-3.2.2-1.1">libswscale4-32bit-3.2.2-1.1</FullProductName>
    </Branch>
    <Relationship ProductReference="ffmpeg-3.2.2-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:ffmpeg-3.2.2-1.1">ffmpeg-3.2.2-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="ffmpeg2-devel-2.8.8-3.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:ffmpeg2-devel-2.8.8-3.1">ffmpeg2-devel-2.8.8-3.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="libavcodec-devel-3.2.2-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:libavcodec-devel-3.2.2-1.1">libavcodec-devel-3.2.2-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="libavcodec56-2.8.8-3.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:libavcodec56-2.8.8-3.1">libavcodec56-2.8.8-3.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="libavcodec56-32bit-2.8.8-3.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:libavcodec56-32bit-2.8.8-3.1">libavcodec56-32bit-2.8.8-3.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="libavcodec57-3.2.2-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:libavcodec57-3.2.2-1.1">libavcodec57-3.2.2-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="libavcodec57-32bit-3.2.2-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:libavcodec57-32bit-3.2.2-1.1">libavcodec57-32bit-3.2.2-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="libavdevice-devel-3.2.2-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:libavdevice-devel-3.2.2-1.1">libavdevice-devel-3.2.2-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="libavdevice56-2.8.8-3.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:libavdevice56-2.8.8-3.1">libavdevice56-2.8.8-3.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="libavdevice56-32bit-2.8.8-3.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:libavdevice56-32bit-2.8.8-3.1">libavdevice56-32bit-2.8.8-3.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="libavdevice57-3.2.2-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:libavdevice57-3.2.2-1.1">libavdevice57-3.2.2-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="libavdevice57-32bit-3.2.2-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:libavdevice57-32bit-3.2.2-1.1">libavdevice57-32bit-3.2.2-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="libavfilter-devel-3.2.2-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:libavfilter-devel-3.2.2-1.1">libavfilter-devel-3.2.2-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="libavfilter5-2.8.8-3.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:libavfilter5-2.8.8-3.1">libavfilter5-2.8.8-3.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="libavfilter5-32bit-2.8.8-3.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:libavfilter5-32bit-2.8.8-3.1">libavfilter5-32bit-2.8.8-3.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="libavfilter6-3.2.2-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:libavfilter6-3.2.2-1.1">libavfilter6-3.2.2-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="libavfilter6-32bit-3.2.2-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:libavfilter6-32bit-3.2.2-1.1">libavfilter6-32bit-3.2.2-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="libavformat-devel-3.2.2-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:libavformat-devel-3.2.2-1.1">libavformat-devel-3.2.2-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="libavformat56-2.8.8-3.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:libavformat56-2.8.8-3.1">libavformat56-2.8.8-3.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="libavformat56-32bit-2.8.8-3.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:libavformat56-32bit-2.8.8-3.1">libavformat56-32bit-2.8.8-3.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="libavformat57-3.2.2-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:libavformat57-3.2.2-1.1">libavformat57-3.2.2-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="libavformat57-32bit-3.2.2-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:libavformat57-32bit-3.2.2-1.1">libavformat57-32bit-3.2.2-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="libavresample-devel-3.2.2-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:libavresample-devel-3.2.2-1.1">libavresample-devel-3.2.2-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="libavresample2-2.8.8-3.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:libavresample2-2.8.8-3.1">libavresample2-2.8.8-3.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="libavresample2-32bit-2.8.8-3.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:libavresample2-32bit-2.8.8-3.1">libavresample2-32bit-2.8.8-3.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="libavresample3-3.2.2-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:libavresample3-3.2.2-1.1">libavresample3-3.2.2-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="libavresample3-32bit-3.2.2-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:libavresample3-32bit-3.2.2-1.1">libavresample3-32bit-3.2.2-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="libavutil-devel-3.2.2-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:libavutil-devel-3.2.2-1.1">libavutil-devel-3.2.2-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="libavutil54-2.8.8-3.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:libavutil54-2.8.8-3.1">libavutil54-2.8.8-3.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="libavutil54-32bit-2.8.8-3.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:libavutil54-32bit-2.8.8-3.1">libavutil54-32bit-2.8.8-3.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="libavutil55-3.2.2-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:libavutil55-3.2.2-1.1">libavutil55-3.2.2-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="libavutil55-32bit-3.2.2-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:libavutil55-32bit-3.2.2-1.1">libavutil55-32bit-3.2.2-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="libpostproc-devel-3.2.2-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:libpostproc-devel-3.2.2-1.1">libpostproc-devel-3.2.2-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="libpostproc53-2.8.8-3.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:libpostproc53-2.8.8-3.1">libpostproc53-2.8.8-3.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="libpostproc53-32bit-2.8.8-3.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:libpostproc53-32bit-2.8.8-3.1">libpostproc53-32bit-2.8.8-3.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="libpostproc54-3.2.2-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:libpostproc54-3.2.2-1.1">libpostproc54-3.2.2-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="libpostproc54-32bit-3.2.2-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:libpostproc54-32bit-3.2.2-1.1">libpostproc54-32bit-3.2.2-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="libswresample-devel-3.2.2-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:libswresample-devel-3.2.2-1.1">libswresample-devel-3.2.2-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="libswresample1-2.8.8-3.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:libswresample1-2.8.8-3.1">libswresample1-2.8.8-3.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="libswresample1-32bit-2.8.8-3.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:libswresample1-32bit-2.8.8-3.1">libswresample1-32bit-2.8.8-3.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="libswresample2-3.2.2-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:libswresample2-3.2.2-1.1">libswresample2-3.2.2-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="libswresample2-32bit-3.2.2-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:libswresample2-32bit-3.2.2-1.1">libswresample2-32bit-3.2.2-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="libswscale-devel-3.2.2-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:libswscale-devel-3.2.2-1.1">libswscale-devel-3.2.2-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="libswscale3-2.8.8-3.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:libswscale3-2.8.8-3.1">libswscale3-2.8.8-3.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="libswscale3-32bit-2.8.8-3.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:libswscale3-32bit-2.8.8-3.1">libswscale3-32bit-2.8.8-3.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="libswscale4-3.2.2-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:libswscale4-3.2.2-1.1">libswscale4-3.2.2-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="libswscale4-32bit-3.2.2-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:libswscale4-32bit-3.2.2-1.1">libswscale4-32bit-3.2.2-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
  </ProductTree>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="1">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">The ljpeg_decode_yuv_scan function in libavcodec/mjpegdec.c in FFmpeg before 2.8.2 omits certain width and height checks, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted MJPEG data.</Note>
    </Notes>
    <CVE>CVE-2015-8216</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:ffmpeg-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ffmpeg2-devel-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavcodec-devel-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavcodec56-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavcodec56-32bit-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavcodec57-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavcodec57-32bit-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavdevice-devel-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavdevice56-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavdevice56-32bit-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavdevice57-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavdevice57-32bit-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavfilter-devel-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavfilter5-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavfilter5-32bit-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavfilter6-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavfilter6-32bit-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavformat-devel-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavformat56-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavformat56-32bit-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavformat57-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavformat57-32bit-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavresample-devel-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavresample2-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavresample2-32bit-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavresample3-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavresample3-32bit-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavutil-devel-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavutil54-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavutil54-32bit-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavutil55-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavutil55-32bit-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libpostproc-devel-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libpostproc53-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libpostproc53-32bit-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libpostproc54-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libpostproc54-32bit-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libswresample-devel-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libswresample1-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libswresample1-32bit-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libswresample2-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libswresample2-32bit-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libswscale-devel-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libswscale3-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libswscale3-32bit-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libswscale4-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libswscale4-32bit-3.2.2-1.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>7.5</BaseScore>
        <Vector>AV:N/AC:L/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2015-8216.html</URL>
        <Description>CVE-2015-8216</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/955346</URL>
        <Description>SUSE Bug 955346</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="2">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">The ff_hevc_parse_sps function in libavcodec/hevc_ps.c in FFmpeg before 2.8.2 does not validate the Chroma Format Indicator, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted High Efficiency Video Coding (HEVC) data.</Note>
    </Notes>
    <CVE>CVE-2015-8217</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:ffmpeg-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ffmpeg2-devel-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavcodec-devel-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavcodec56-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavcodec56-32bit-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavcodec57-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavcodec57-32bit-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavdevice-devel-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavdevice56-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavdevice56-32bit-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavdevice57-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavdevice57-32bit-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavfilter-devel-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavfilter5-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavfilter5-32bit-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavfilter6-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavfilter6-32bit-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavformat-devel-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavformat56-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavformat56-32bit-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavformat57-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavformat57-32bit-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavresample-devel-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavresample2-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavresample2-32bit-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavresample3-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavresample3-32bit-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavutil-devel-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavutil54-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavutil54-32bit-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavutil55-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavutil55-32bit-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libpostproc-devel-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libpostproc53-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libpostproc53-32bit-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libpostproc54-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libpostproc54-32bit-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libswresample-devel-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libswresample1-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libswresample1-32bit-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libswresample2-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libswresample2-32bit-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libswscale-devel-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libswscale3-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libswscale3-32bit-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libswscale4-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libswscale4-32bit-3.2.2-1.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>7.5</BaseScore>
        <Vector>AV:N/AC:L/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2015-8217.html</URL>
        <Description>CVE-2015-8217</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/955347</URL>
        <Description>SUSE Bug 955347</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="3">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">The decode_uncompressed function in libavcodec/faxcompr.c in FFmpeg before 2.8.2 does not validate uncompressed runs, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted CCITT FAX data.</Note>
    </Notes>
    <CVE>CVE-2015-8218</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:ffmpeg-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ffmpeg2-devel-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavcodec-devel-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavcodec56-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavcodec56-32bit-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavcodec57-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavcodec57-32bit-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavdevice-devel-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavdevice56-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavdevice56-32bit-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavdevice57-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavdevice57-32bit-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavfilter-devel-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavfilter5-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavfilter5-32bit-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavfilter6-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavfilter6-32bit-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavformat-devel-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavformat56-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavformat56-32bit-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavformat57-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavformat57-32bit-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavresample-devel-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavresample2-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavresample2-32bit-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavresample3-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavresample3-32bit-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavutil-devel-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavutil54-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavutil54-32bit-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavutil55-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavutil55-32bit-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libpostproc-devel-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libpostproc53-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libpostproc53-32bit-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libpostproc54-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libpostproc54-32bit-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libswresample-devel-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libswresample1-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libswresample1-32bit-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libswresample2-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libswresample2-32bit-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libswscale-devel-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libswscale3-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libswscale3-32bit-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libswscale4-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libswscale4-32bit-3.2.2-1.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>6.8</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2015-8218.html</URL>
        <Description>CVE-2015-8218</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/955348</URL>
        <Description>SUSE Bug 955348</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="4">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">The init_tile function in libavcodec/jpeg2000dec.c in FFmpeg before 2.8.2 does not enforce minimum-value and maximum-value constraints on tile coordinates, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted JPEG 2000 data.</Note>
    </Notes>
    <CVE>CVE-2015-8219</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:ffmpeg-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ffmpeg2-devel-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavcodec-devel-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavcodec56-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavcodec56-32bit-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavcodec57-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavcodec57-32bit-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavdevice-devel-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavdevice56-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavdevice56-32bit-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavdevice57-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavdevice57-32bit-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavfilter-devel-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavfilter5-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavfilter5-32bit-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavfilter6-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavfilter6-32bit-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavformat-devel-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavformat56-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavformat56-32bit-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavformat57-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavformat57-32bit-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavresample-devel-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavresample2-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavresample2-32bit-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavresample3-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavresample3-32bit-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavutil-devel-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavutil54-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavutil54-32bit-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavutil55-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavutil55-32bit-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libpostproc-devel-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libpostproc53-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libpostproc53-32bit-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libpostproc54-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libpostproc54-32bit-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libswresample-devel-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libswresample1-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libswresample1-32bit-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libswresample2-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libswresample2-32bit-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libswscale-devel-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libswscale3-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libswscale3-32bit-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libswscale4-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libswscale4-32bit-3.2.2-1.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>7.5</BaseScore>
        <Vector>AV:N/AC:L/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2015-8219.html</URL>
        <Description>CVE-2015-8219</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/955350</URL>
        <Description>SUSE Bug 955350</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="5">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">The jpeg2000_read_main_headers function in libavcodec/jpeg2000dec.c in FFmpeg before 2.6.5, 2.7.x before 2.7.3, and 2.8.x through 2.8.2 does not enforce uniqueness of the SIZ marker in a JPEG 2000 image, which allows remote attackers to cause a denial of service (out-of-bounds heap-memory access) or possibly have unspecified other impact via a crafted image with two or more of these markers.</Note>
    </Notes>
    <CVE>CVE-2015-8363</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:ffmpeg-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ffmpeg2-devel-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavcodec-devel-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavcodec56-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavcodec56-32bit-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavcodec57-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavcodec57-32bit-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavdevice-devel-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavdevice56-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavdevice56-32bit-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavdevice57-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavdevice57-32bit-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavfilter-devel-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavfilter5-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavfilter5-32bit-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavfilter6-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavfilter6-32bit-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavformat-devel-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavformat56-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavformat56-32bit-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavformat57-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavformat57-32bit-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavresample-devel-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavresample2-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavresample2-32bit-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavresample3-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavresample3-32bit-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavutil-devel-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavutil54-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavutil54-32bit-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavutil55-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavutil55-32bit-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libpostproc-devel-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libpostproc53-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libpostproc53-32bit-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libpostproc54-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libpostproc54-32bit-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libswresample-devel-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libswresample1-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libswresample1-32bit-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libswresample2-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libswresample2-32bit-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libswscale-devel-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libswscale3-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libswscale3-32bit-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libswscale4-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libswscale4-32bit-3.2.2-1.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>6.8</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2015-8363.html</URL>
        <Description>CVE-2015-8363</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/957114</URL>
        <Description>SUSE Bug 957114</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="6">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Integer overflow in the ff_ivi_init_planes function in libavcodec/ivi.c in FFmpeg before 2.6.5, 2.7.x before 2.7.3, and 2.8.x through 2.8.2 allows remote attackers to cause a denial of service (out-of-bounds heap-memory access) or possibly have unspecified other impact via crafted image dimensions in Indeo Video Interactive data.</Note>
    </Notes>
    <CVE>CVE-2015-8364</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:ffmpeg-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ffmpeg2-devel-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavcodec-devel-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavcodec56-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavcodec56-32bit-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavcodec57-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavcodec57-32bit-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavdevice-devel-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavdevice56-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavdevice56-32bit-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavdevice57-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavdevice57-32bit-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavfilter-devel-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavfilter5-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavfilter5-32bit-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavfilter6-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavfilter6-32bit-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavformat-devel-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavformat56-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavformat56-32bit-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavformat57-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavformat57-32bit-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavresample-devel-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavresample2-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavresample2-32bit-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavresample3-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavresample3-32bit-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavutil-devel-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavutil54-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavutil54-32bit-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavutil55-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavutil55-32bit-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libpostproc-devel-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libpostproc53-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libpostproc53-32bit-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libpostproc54-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libpostproc54-32bit-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libswresample-devel-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libswresample1-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libswresample1-32bit-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libswresample2-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libswresample2-32bit-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libswscale-devel-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libswscale3-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libswscale3-32bit-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libswscale4-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libswscale4-32bit-3.2.2-1.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>6.8</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2015-8364.html</URL>
        <Description>CVE-2015-8364</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/957115</URL>
        <Description>SUSE Bug 957115</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="7">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">The smka_decode_frame function in libavcodec/smacker.c in FFmpeg before 2.6.5, 2.7.x before 2.7.3, and 2.8.x through 2.8.2 does not verify that the data size is consistent with the number of channels, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted Smacker data.</Note>
    </Notes>
    <CVE>CVE-2015-8365</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:ffmpeg-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ffmpeg2-devel-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavcodec-devel-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavcodec56-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavcodec56-32bit-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavcodec57-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavcodec57-32bit-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavdevice-devel-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavdevice56-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavdevice56-32bit-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavdevice57-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavdevice57-32bit-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavfilter-devel-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavfilter5-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavfilter5-32bit-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavfilter6-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavfilter6-32bit-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavformat-devel-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavformat56-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavformat56-32bit-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavformat57-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavformat57-32bit-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavresample-devel-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavresample2-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavresample2-32bit-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavresample3-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavresample3-32bit-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavutil-devel-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavutil54-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavutil54-32bit-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavutil55-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavutil55-32bit-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libpostproc-devel-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libpostproc53-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libpostproc53-32bit-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libpostproc54-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libpostproc54-32bit-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libswresample-devel-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libswresample1-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libswresample1-32bit-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libswresample2-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libswresample2-32bit-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libswscale-devel-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libswscale3-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libswscale3-32bit-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libswscale4-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libswscale4-32bit-3.2.2-1.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>6.8</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2015-8365.html</URL>
        <Description>CVE-2015-8365</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/957116</URL>
        <Description>SUSE Bug 957116</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="8">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">The h264_slice_header_init function in libavcodec/h264_slice.c in FFmpeg before 2.8.3 does not validate the relationship between the number of threads and the number of slices, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted H.264 data.</Note>
    </Notes>
    <CVE>CVE-2015-8661</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:ffmpeg-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ffmpeg2-devel-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavcodec-devel-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavcodec56-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavcodec56-32bit-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavcodec57-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavcodec57-32bit-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavdevice-devel-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavdevice56-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavdevice56-32bit-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavdevice57-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavdevice57-32bit-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavfilter-devel-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavfilter5-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavfilter5-32bit-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavfilter6-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavfilter6-32bit-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavformat-devel-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavformat56-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavformat56-32bit-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavformat57-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavformat57-32bit-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavresample-devel-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavresample2-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavresample2-32bit-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavresample3-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavresample3-32bit-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavutil-devel-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavutil54-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavutil54-32bit-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavutil55-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavutil55-32bit-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libpostproc-devel-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libpostproc53-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libpostproc53-32bit-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libpostproc54-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libpostproc54-32bit-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libswresample-devel-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libswresample1-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libswresample1-32bit-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libswresample2-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libswresample2-32bit-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libswscale-devel-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libswscale3-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libswscale3-32bit-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libswscale4-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libswscale4-32bit-3.2.2-1.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>7.5</BaseScore>
        <Vector>AV:N/AC:L/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2015-8661.html</URL>
        <Description>CVE-2015-8661</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/960385</URL>
        <Description>SUSE Bug 960385</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="9">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">The ff_dwt_decode function in libavcodec/jpeg2000dwt.c in FFmpeg before 2.8.4 does not validate the number of decomposition levels before proceeding with Discrete Wavelet Transform decoding, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted JPEG 2000 data.</Note>
    </Notes>
    <CVE>CVE-2015-8662</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:ffmpeg-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ffmpeg2-devel-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavcodec-devel-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavcodec56-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavcodec56-32bit-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavcodec57-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavcodec57-32bit-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavdevice-devel-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavdevice56-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavdevice56-32bit-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavdevice57-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavdevice57-32bit-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavfilter-devel-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavfilter5-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavfilter5-32bit-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavfilter6-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavfilter6-32bit-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavformat-devel-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavformat56-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavformat56-32bit-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavformat57-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavformat57-32bit-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavresample-devel-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavresample2-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavresample2-32bit-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavresample3-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavresample3-32bit-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavutil-devel-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavutil54-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavutil54-32bit-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavutil55-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavutil55-32bit-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libpostproc-devel-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libpostproc53-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libpostproc53-32bit-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libpostproc54-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libpostproc54-32bit-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libswresample-devel-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libswresample1-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libswresample1-32bit-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libswresample2-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libswresample2-32bit-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libswscale-devel-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libswscale3-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libswscale3-32bit-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libswscale4-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libswscale4-32bit-3.2.2-1.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>7.5</BaseScore>
        <Vector>AV:N/AC:L/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2015-8662.html</URL>
        <Description>CVE-2015-8662</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/960384</URL>
        <Description>SUSE Bug 960384</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="10">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">The ff_get_buffer function in libavcodec/utils.c in FFmpeg before 2.8.4 preserves width and height values after a failure, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via a crafted .mov file.</Note>
    </Notes>
    <CVE>CVE-2015-8663</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:ffmpeg-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ffmpeg2-devel-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavcodec-devel-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavcodec56-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavcodec56-32bit-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavcodec57-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavcodec57-32bit-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavdevice-devel-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavdevice56-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavdevice56-32bit-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavdevice57-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavdevice57-32bit-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavfilter-devel-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavfilter5-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavfilter5-32bit-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavfilter6-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavfilter6-32bit-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavformat-devel-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavformat56-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavformat56-32bit-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavformat57-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavformat57-32bit-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavresample-devel-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavresample2-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavresample2-32bit-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavresample3-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavresample3-32bit-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavutil-devel-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavutil54-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavutil54-32bit-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavutil55-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavutil55-32bit-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libpostproc-devel-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libpostproc53-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libpostproc53-32bit-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libpostproc54-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libpostproc54-32bit-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libswresample-devel-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libswresample1-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libswresample1-32bit-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libswresample2-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libswresample2-32bit-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libswscale-devel-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libswscale3-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libswscale3-32bit-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libswscale4-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libswscale4-32bit-3.2.2-1.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>7.5</BaseScore>
        <Vector>AV:N/AC:L/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2015-8663.html</URL>
        <Description>CVE-2015-8663</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/960383</URL>
        <Description>SUSE Bug 960383</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="11">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">FFmpeg 2.x allows remote attackers to conduct cross-origin attacks and read arbitrary files by using the concat protocol in an HTTP Live Streaming (HLS) M3U8 file, leading to an external HTTP request in which the URL string contains the first line of a local file.</Note>
    </Notes>
    <CVE>CVE-2016-1897</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:ffmpeg-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ffmpeg2-devel-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavcodec-devel-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavcodec56-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavcodec56-32bit-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavcodec57-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavcodec57-32bit-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavdevice-devel-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavdevice56-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavdevice56-32bit-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavdevice57-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavdevice57-32bit-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavfilter-devel-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavfilter5-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavfilter5-32bit-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavfilter6-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavfilter6-32bit-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavformat-devel-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavformat56-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavformat56-32bit-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavformat57-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavformat57-32bit-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavresample-devel-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavresample2-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavresample2-32bit-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavresample3-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavresample3-32bit-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavutil-devel-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavutil54-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavutil54-32bit-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavutil55-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavutil55-32bit-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libpostproc-devel-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libpostproc53-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libpostproc53-32bit-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libpostproc54-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libpostproc54-32bit-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libswresample-devel-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libswresample1-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libswresample1-32bit-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libswresample2-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libswresample2-32bit-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libswscale-devel-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libswscale3-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libswscale3-32bit-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libswscale4-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libswscale4-32bit-3.2.2-1.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>4.3</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:P/I:N/A:N</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-1897.html</URL>
        <Description>CVE-2016-1897</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/961937</URL>
        <Description>SUSE Bug 961937</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="12">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">FFmpeg 2.x allows remote attackers to conduct cross-origin attacks and read arbitrary files by using the subfile protocol in an HTTP Live Streaming (HLS) M3U8 file, leading to an external HTTP request in which the URL string contains an arbitrary line of a local file.</Note>
    </Notes>
    <CVE>CVE-2016-1898</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:ffmpeg-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ffmpeg2-devel-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavcodec-devel-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavcodec56-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavcodec56-32bit-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavcodec57-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavcodec57-32bit-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavdevice-devel-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavdevice56-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavdevice56-32bit-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavdevice57-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavdevice57-32bit-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavfilter-devel-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavfilter5-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavfilter5-32bit-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavfilter6-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavfilter6-32bit-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavformat-devel-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavformat56-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavformat56-32bit-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavformat57-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavformat57-32bit-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavresample-devel-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavresample2-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavresample2-32bit-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavresample3-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavresample3-32bit-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavutil-devel-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavutil54-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavutil54-32bit-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavutil55-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libavutil55-32bit-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libpostproc-devel-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libpostproc53-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libpostproc53-32bit-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libpostproc54-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libpostproc54-32bit-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libswresample-devel-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libswresample1-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libswresample1-32bit-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libswresample2-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libswresample2-32bit-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libswscale-devel-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libswscale3-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libswscale3-32bit-2.8.8-3.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libswscale4-3.2.2-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libswscale4-32bit-3.2.2-1.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>4.3</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:P/I:N/A:N</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-1898.html</URL>
        <Description>CVE-2016-1898</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/961937</URL>
        <Description>SUSE Bug 961937</Description>
      </Reference>
    </References>
  </Vulnerability>
</cvrfdoc>
