PT-2018-2293 · FFmpeg+2 · Ffmpeg+2

Alexandru Razvan Caciulescu

+3

·

Publicado

2018-06-27

·

Atualizado

2026-02-06

·

CVE-2018-13302

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions FFmpeg versions prior to 4.0.1
Description The issue is related to the improper handling of frame types, other than EAC3 FRAME TYPE INDEPENDENT, that have multiple independent substreams in the handle eac3 function. This may trigger an out-of-array access while converting a crafted AVI file to MPEG4, potentially leading to a denial of service or allowing a remote attacker to execute arbitrary code using a specially crafted AVI file.
Recommendations For FFmpeg version 4.0.1, update to a version that contains a fix for this issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Improper Validation of Array Index

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2018-2047
BDU:2019-00420
CLEANSTART-2026-EZ98723
CLEANSTART-2026-PS82605
CLEANSTART-2026-XE32069
CVE-2018-13302
DSA-4249-1
MGASA-2018-0319
SUSE-SU-2018:2305-1
SUSE-SU-2018_2305-1

Produtos afetados

Alt Linux
Ffmpeg
Suse