PT-2018-3996 · FFmpeg+1 · Ffmpeg+1
Paul Ch
·
Published
2018-07-05
·
Updated
2026-02-06
·
CVE-2018-1999014
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
FFmpeg versions prior to bab0716c7f4793ec42e05a5aa7e80d82a0dd4e75
Description
The issue is related to an out of array access vulnerability in the MXF format demuxer, which can result in a denial of service (DoS). This can be exploited via a specially crafted MXF file provided as input. The vulnerability is related to reading beyond the valid boundaries of a data buffer.
Recommendations
For versions prior to bab0716c7f4793ec42e05a5aa7e80d82a0dd4e75, update to a version that includes the fix, such as bab0716c7f4793ec42e05a5aa7e80d82a0dd4e75 or later. As a temporary workaround, consider restricting the use of MXF files or disabling the MXF format demuxer until a patch is applied. Avoid using the vulnerable MXF format demuxer with untrusted input files.
Fix
DoS
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Ffmpeg