PT-2018-3998 · FFmpeg+2 · Ffmpeg+2

Paul Ch

·

Published

2018-07-05

·

Updated

2026-02-06

·

CVE-2018-1999012

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions FFmpeg versions prior to 9807d3976be0e92e4ece3b4b1701be894cd7c2e1
Description The issue is related to an infinite loop vulnerability in the pva format demuxer. This can be exploited by providing a specially crafted PVA file as input, allowing attackers to consume excessive amounts of resources like CPU and RAM, potentially leading to a denial of service. The vulnerability can be exploited remotely.
Recommendations For versions prior to 9807d3976be0e92e4ece3b4b1701be894cd7c2e1, update to a version that includes the fix, such as 9807d3976be0e92e4ece3b4b1701be894cd7c2e1 or later. As a temporary workaround, consider restricting the use of the pva format demuxer to minimize the risk of exploitation. Avoid using the pva format demuxer with untrusted input files until the issue is resolved.

Fix

Infinite Loop

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2018-2047
BDU:2024-09058
CLEANSTART-2026-EZ98723
CLEANSTART-2026-PS82605
CLEANSTART-2026-XE32069
CVE-2018-1999012
DLA-1740-1
DSA-4249-1
SUSE-SU-2018:2305-1

Affected Products

Alt Linux
Ffmpeg
Suse