PT-2018-4001 · FFmpeg+1 · Ffmpeg+1

Alexandru Razvan Caciulescu

+3

·

Publicado

2018-07-05

·

Atualizado

2026-02-06

·

CVE-2018-13304

CVSS v2.0

7.8

Alta

VetorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions FFmpeg version 4.0.1
Description The issue is related to improper maintenance of consistency between the context profile field and studio profile in libavcodec, which may trigger an assertion failure when converting a crafted AVI file to MPEG4. This can lead to a denial of service. The affected components include error resilience.c, h263dec.c, and mpeg4videodec.c. A remote attacker can exploit this issue using a specially crafted AVI file.
Recommendations For FFmpeg version 4.0.1, consider disabling the affected components, such as error resilience.c, h263dec.c, and mpeg4videodec.c, as a temporary workaround to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Assertion Failure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2018-2047
BDU:2024-09061
CLEANSTART-2026-EZ98723
CLEANSTART-2026-PS82605
CLEANSTART-2026-XE32069
CVE-2018-13304

Produtos afetados

Alt Linux
Ffmpeg