PT-2018-3996 · FFmpeg+1 · Ffmpeg+1
Paul Ch
·
Publicado
2018-07-05
·
Atualizado
2026-02-06
·
CVE-2018-1999014
CVSS v2.0
7.8
Alta
| Vetor | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
FFmpeg versions prior to bab0716c7f4793ec42e05a5aa7e80d82a0dd4e75
Description
The issue is related to an out of array access vulnerability in the MXF format demuxer, which can result in a denial of service (DoS). This can be exploited via a specially crafted MXF file provided as input. The vulnerability is related to reading beyond the valid boundaries of a data buffer.
Recommendations
For versions prior to bab0716c7f4793ec42e05a5aa7e80d82a0dd4e75, update to a version that includes the fix, such as bab0716c7f4793ec42e05a5aa7e80d82a0dd4e75 or later. As a temporary workaround, consider restricting the use of MXF files or disabling the MXF format demuxer until a patch is applied. Avoid using the vulnerable MXF format demuxer with untrusted input files.
Correção
DoS
Out of bounds Read
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Alt Linux
Ffmpeg