PT-2018-3402 · FFmpeg+4 · Ffmpeg+4
Chen Hongxu
·
Publicado
2018-08-23
·
Atualizado
2026-02-06
·
CVE-2018-15822
CVSS v3.1
9.8
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
FFmpeg versions through 2.8
Description:
The issue is related to the
flv write packet function in the FFmpeg library, which lacks a check for an empty audio packet. This can lead to an assertion failure. Exploitation of this issue may allow a remote attacker to cause a denial of service.Recommendations:
For FFmpeg versions through 2.8, consider updating to a version that includes a fix for this issue, as the current version may allow for a denial of service attack due to the lack of checking for empty audio packets in the
flv write packet function.Correção
Assertion Failure
RCE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Alt Linux
Ffmpeg
Linuxmint
Suse
Ubuntu