Ubuntu Security Notice 630-1 – It was discovered that ffmpeg did not correctly handle STR file demuxing. If a user were tricked into processing a malicious STR file, a remote attacker could execute arbitrary code with user privileges via applications linked against ffmpeg.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/68581/USN-630-1.txt
Source: https://packetstormsecurity.com/files/68581/Ubuntu-Security-Notice-630-1.html