PT-2018-3998 · FFmpeg+2 · Ffmpeg+2
Paul Ch
·
Published
2018-07-05
·
Updated
2026-02-06
·
CVE-2018-1999012
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
FFmpeg versions prior to 9807d3976be0e92e4ece3b4b1701be894cd7c2e1
Description
The issue is related to an infinite loop vulnerability in the pva format demuxer. This can be exploited by providing a specially crafted PVA file as input, allowing attackers to consume excessive amounts of resources like CPU and RAM, potentially leading to a denial of service. The vulnerability can be exploited remotely.
Recommendations
For versions prior to 9807d3976be0e92e4ece3b4b1701be894cd7c2e1, update to a version that includes the fix, such as 9807d3976be0e92e4ece3b4b1701be894cd7c2e1 or later. As a temporary workaround, consider restricting the use of the pva format demuxer to minimize the risk of exploitation. Avoid using the pva format demuxer with untrusted input files until the issue is resolved.
Fix
Infinite Loop
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Ffmpeg
Suse