PT-2016-3166 · FFmpeg+2 · Ffmpeg+2
Wangchu
+1
·
Publicado
2016-08-25
·
Atualizado
2024-06-15
·
CVE-2017-14059
CVSS v2.0
7.1
Alta
| Vetor | AV:N/AC:M/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
FFmpeg version 3.3.3
Description
The issue is related to a lack of an EOF check in the
cine read header() function, which can cause huge CPU and memory consumption. This occurs when a crafted CINE file with a large "duration" field in the header but insufficient backing data is provided, leading to excessive resource usage by the image-offset parsing loop. The vulnerability can be exploited by a remote attacker to cause a denial of service.Recommendations
For FFmpeg version 3.3.3, consider disabling the
cine read header() function until a patch is available to prevent potential denial of service attacks. Restrict access to CINE files with large "duration" fields to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.DoS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Alt Linux
Ffmpeg
Suse