PT-2018-3989 · FFmpeg+1 · Ffmpeg+1

Published

2018-12-22

·

Updated

2026-02-06

·

CVE-2019-1000016

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions FFMPEG version 4.1
Description The issue is related to improper validation of array indices in the libavcodec/cbs av1.c component of the FFmpeg library. This can be exploited via a specially crafted AV1 file, potentially leading to a denial of service. The vulnerability is exploitable by providing a specially crafted AV1 file as input.
Recommendations For FFMPEG version 4.1, update to a version that includes the fix committed after b97a4b658814b2de8b9f2a3bce491c002d34de31 to resolve the issue. As a temporary workaround, consider restricting the use of the libavcodec/cbs av1.c component when processing AV1 files until a patch is available.

Fix

DoS

Improper Validation of Array Index

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2019-1275
BDU:2024-09049
CLEANSTART-2026-EZ98723
CLEANSTART-2026-PS82605
CLEANSTART-2026-XE32069
CVE-2019-1000016

Affected Products

Alt Linux
Ffmpeg