PT-2017-4347 · FFmpeg+2 · Ffmpeg+2

Bingchang Liu

·

Publicado

2017-07-17

·

Atualizado

2024-06-15

·

CVE-2017-11399

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: FFmpeg versions 2.4 through 3.3.2
Description: The issue is related to an integer overflow in the ape decode frame function in libavcodec/apedec.c of the FFmpeg library. This can be exploited by a remote attacker using a specially crafted APE file, potentially leading to a denial of service (out-of-array access and application crash) or other unspecified impacts. The exploitation may allow the attacker to access confidential data, compromise its integrity, or cause a service disruption.
Recommendations: For FFmpeg versions 2.4 through 3.3.2, consider updating to a version where this issue is fixed, as using a crafted APE file can lead to a denial of service or other unspecified impacts. As a temporary workaround, consider restricting the use of the ape decode frame function in libavcodec/apedec.c until a patch is available. Avoid using specially crafted APE files with the affected FFmpeg versions to minimize the risk of exploitation.

Exploit

Correção

DoS

Out of bounds Read

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2017-1960
BDU:2024-09065
CVE-2017-11399
DSA-3957-1
MGASA-2018-0008
OPENSUSE-SU-2017_2502-1
OPENSUSE-SU-2024:10754-1

Produtos afetados

Alt Linux
Ffmpeg
Suse