PT-2018-3996 · FFmpeg+1 · Ffmpeg+1

Paul Ch

·

Published

2018-07-05

·

Updated

2026-02-06

·

CVE-2018-1999014

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions FFmpeg versions prior to bab0716c7f4793ec42e05a5aa7e80d82a0dd4e75
Description The issue is related to an out of array access vulnerability in the MXF format demuxer, which can result in a denial of service (DoS). This can be exploited via a specially crafted MXF file provided as input. The vulnerability is related to reading beyond the valid boundaries of a data buffer.
Recommendations For versions prior to bab0716c7f4793ec42e05a5aa7e80d82a0dd4e75, update to a version that includes the fix, such as bab0716c7f4793ec42e05a5aa7e80d82a0dd4e75 or later. As a temporary workaround, consider restricting the use of MXF files or disabling the MXF format demuxer until a patch is applied. Avoid using the vulnerable MXF format demuxer with untrusted input files.

Fix

DoS

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2018-2047
BDU:2024-09056
CLEANSTART-2026-EZ98723
CLEANSTART-2026-PS82605
CLEANSTART-2026-XE32069
CVE-2018-1999014

Affected Products

Alt Linux
Ffmpeg