PT-2016-3166 · FFmpeg+2 · Ffmpeg+2

Wangchu

+1

·

Published

2016-08-25

·

Updated

2024-06-15

·

CVE-2017-14059

CVSS v2.0

7.1

High

VectorAV:N/AC:M/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions FFmpeg version 3.3.3
Description The issue is related to a lack of an EOF check in the cine read header() function, which can cause huge CPU and memory consumption. This occurs when a crafted CINE file with a large "duration" field in the header but insufficient backing data is provided, leading to excessive resource usage by the image-offset parsing loop. The vulnerability can be exploited by a remote attacker to cause a denial of service.
Recommendations For FFmpeg version 3.3.3, consider disabling the cine read header() function until a patch is available to prevent potential denial of service attacks. Restrict access to CINE files with large "duration" fields to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2017-2226
BDU:2017-02089
CVE-2017-14059
DSA-3996-1
MGASA-2018-0008
OPENSUSE-SU-2017_2502-1
OPENSUSE-SU-2024:10754-1

Affected Products

Alt Linux
Ffmpeg
Suse