PT-2017-2973 · FFmpeg+2 · Ffmpeg+2
Wangchu
+1
·
Publicado
2017-09-08
·
Atualizado
2024-06-15
·
CVE-2017-14222
CVSS v2.0
7.1
Alta
| Vetor | AV:N/AC:M/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
FFmpeg version 3.3.3
Description
The issue is related to a lack of an End of File (EOF) check in the
read tfra() function, which can cause huge CPU and memory consumption. This occurs when a crafted MOV file with a large item count field in the header but insufficient backing data is processed, leading to a loop that consumes significant resources. The vulnerability can be exploited by a remote attacker to cause a denial of service.Recommendations
For FFmpeg version 3.3.3, consider applying a patch or updating to a newer version that includes a fix for the
read tfra() function to add an EOF check and prevent excessive resource consumption. As a temporary workaround, consider restricting the processing of MOV files with large item count fields to minimize the risk of exploitation.Correção
DoS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Alt Linux
Ffmpeg
Suse