PT-2018-11727 · FFmpeg+2 · Ffmpeg+2

Alexandru Razvan Caciulescu

+3

·

Published

2018-07-05

·

Updated

2026-02-06

·

CVE-2018-13300

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions FFmpeg versions 3.2 and 4.0.1
Description The issue arises from an improper argument (AVCodecParameters) passed to the avpriv request sample function in the handle eac3 function, potentially triggering an out-of-array read when converting a crafted AVI file to MPEG4. This could lead to a denial of service and possibly an information disclosure.
Recommendations For FFmpeg version 3.2, update to a version that includes a fix for this issue. For FFmpeg version 4.0.1, update to a version that includes a fix for this issue.

Fix

DoS

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2018-2047
CLEANSTART-2026-EZ98723
CLEANSTART-2026-PS82605
CLEANSTART-2026-XE32069
CVE-2018-13300
DSA-4249-1
MGASA-2018-0319
OPENSUSE-SU-2018_2723-1
OPENSUSE-SU-2019:1066-1
OPENSUSE-SU-2024:10754-1
SUSE-SU-2018:3609-1

Affected Products

Alt Linux
Ffmpeg
Suse