PT-2018-3998 · FFmpeg+2 · Ffmpeg+2
Paul Ch
·
Publicado
2018-07-05
·
Atualizado
2026-02-06
·
CVE-2018-1999012
CVSS v2.0
7.8
Alta
| Vetor | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
FFmpeg versions prior to 9807d3976be0e92e4ece3b4b1701be894cd7c2e1
Description
The issue is related to an infinite loop vulnerability in the pva format demuxer. This can be exploited by providing a specially crafted PVA file as input, allowing attackers to consume excessive amounts of resources like CPU and RAM, potentially leading to a denial of service. The vulnerability can be exploited remotely.
Recommendations
For versions prior to 9807d3976be0e92e4ece3b4b1701be894cd7c2e1, update to a version that includes the fix, such as 9807d3976be0e92e4ece3b4b1701be894cd7c2e1 or later. As a temporary workaround, consider restricting the use of the pva format demuxer to minimize the risk of exploitation. Avoid using the pva format demuxer with untrusted input files until the issue is resolved.
Correção
Infinite Loop
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Alt Linux
Ffmpeg
Suse