PT-2016-3167 · FFmpeg+2 · Ffmpeg+2

Wangchu

+1

·

Published

2016-08-25

·

Updated

2024-06-15

·

CVE-2017-14057

CVSS v2.0

7.1

High

VectorAV:N/AC:M/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions FFmpeg version 3.3.3
Description The issue is related to a lack of an End of File (EOF) check in the asf read marker() function, which can cause significant CPU and memory consumption. This occurs when a crafted ASF file with a large "name len" or "count" field in the header but insufficient backing data is processed, leading to loops over the name and markers consuming huge resources.
Recommendations For FFmpeg version 3.3.3, consider disabling the asf read marker() function as a temporary workaround until a patch is available to prevent potential denial-of-service attacks. Restrict access to ASF files with large "name len" or "count" fields to minimize the risk of exploitation. Avoid using the name len and count fields in the ASF file header until the issue is resolved.

Exploit

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2017-2226
BDU:2017-02090
CVE-2017-14057
DLA-1630-1
DSA-3996-1
MGASA-2018-0008
OPENSUSE-SU-2017_2502-1
OPENSUSE-SU-2024:10754-1

Affected Products

Alt Linux
Ffmpeg
Suse