PT-2018-11727 · FFmpeg+2 · Ffmpeg+2

Alexandru Razvan Caciulescu

+3

·

Publicado

2018-07-05

·

Atualizado

2026-02-06

·

CVE-2018-13300

CVSS v3.1

8.1

Alta

VetorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions FFmpeg versions 3.2 and 4.0.1
Description The issue arises from an improper argument (AVCodecParameters) passed to the avpriv request sample function in the handle eac3 function, potentially triggering an out-of-array read when converting a crafted AVI file to MPEG4. This could lead to a denial of service and possibly an information disclosure.
Recommendations For FFmpeg version 3.2, update to a version that includes a fix for this issue. For FFmpeg version 4.0.1, update to a version that includes a fix for this issue.

Correção

DoS

Out of bounds Read

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2018-2047
CLEANSTART-2026-EZ98723
CLEANSTART-2026-PS82605
CLEANSTART-2026-XE32069
CVE-2018-13300
DSA-4249-1
MGASA-2018-0319
OPENSUSE-SU-2018_2723-1
OPENSUSE-SU-2019:1066-1
OPENSUSE-SU-2024:10754-1
SUSE-SU-2018:3609-1

Produtos afetados

Alt Linux
Ffmpeg
Suse