PT-2017-19067 · FFmpeg+1 · Ffmpeg+1

Yihan Lian

·

Published

2017-08-01

·

Updated

2018-01-17

·

CVE-2017-9608

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions FFmpeg versions prior to 3.2.6 FFmpeg version 3.3.x prior to 3.3.3
Description The issue allows remote attackers to cause a denial of service, specifically a NULL pointer dereference, by using a crafted mov file. This is related to the dnxhd decoder in FFmpeg.
Recommendations For FFmpeg versions prior to 3.2.6, update to version 3.2.6 or later. For FFmpeg version 3.3.x prior to 3.3.3, update to version 3.3.3 or later.

Exploit

Fix

DoS

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2017-1960
CVE-2017-9608
DSA-3957-1
MGASA-2017-0262

Affected Products

Alt Linux
Ffmpeg