PT-2018-5227 · FFmpeg+2 · Ffmpeg+3

Jan Ruge

·

Publicado

2017-02-09

·

Atualizado

2019-03-31

·

CVE-2017-1000460

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions libav version 13 dev0 ffmpeg version n3.4 chromium versions prior to 56 (before Feb 13, 2017)
Description The issue arises from the return value of init get bits being ignored, leading to get ue golomb(&gb) being called on an uninitialized get bits context. This results in a NULL deref exception.
Recommendations For libav version 13 dev0, ensure proper initialization of the get bits context before calling get ue golomb(&gb). For ffmpeg version n3.4, verify the return value of init get bits to prevent calling get ue golomb(&gb) on an uninitialized context. For chromium versions prior to 56 (before Feb 13, 2017), update to a version released after Feb 13, 2017, to ensure the issue is resolved.

Exploit

Correção

NULL Pointer Dereference

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2017-1150
CVE-2017-1000460
DLA-1740-1

Produtos afetados

Alt Linux
Chromium
Ffmpeg
Libav