PT-2016-3166 · FFmpeg+2 · Ffmpeg+2
Wangchu
+1
·
Published
2016-08-25
·
Updated
2024-06-15
·
CVE-2017-14059
CVSS v2.0
7.1
High
| Vector | AV:N/AC:M/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
FFmpeg version 3.3.3
Description
The issue is related to a lack of an EOF check in the
cine read header() function, which can cause huge CPU and memory consumption. This occurs when a crafted CINE file with a large "duration" field in the header but insufficient backing data is provided, leading to excessive resource usage by the image-offset parsing loop. The vulnerability can be exploited by a remote attacker to cause a denial of service.Recommendations
For FFmpeg version 3.3.3, consider disabling the
cine read header() function until a patch is available to prevent potential denial of service attacks. Restrict access to CINE files with large "duration" fields to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Ffmpeg
Suse