PT-2015-3159 · FFmpeg+1 · Ffmpeg+1

Publicado

2015-12-24

·

Atualizado

2024-06-15

·

CVE-2015-8663

CVSS v3.1

8.3

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions FFmpeg versions prior to 2.8.4
Description The issue is related to the ff get buffer function in libavcodec/utils.c, which preserves width and height values after a failure. This allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via a crafted .mov file.
Recommendations For versions prior to 2.8.4, update to version 2.8.4 or later to resolve the issue. As a temporary workaround, consider restricting the use of the ff get buffer function until a patch is available. Avoid using crafted .mov files that could exploit this issue until the update is applied.

Correção

DoS

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2016-00375
CVE-2015-8663
DLA-1611-1
MGASA-2016-0018
OPENSUSE-SU-2016_0089-1
OPENSUSE-SU-2024:10243-1
OPENSUSE-SU-2024:10754-1

Produtos afetados

Ffmpeg
Suse