PT-2018-4001 · FFmpeg+1 · Ffmpeg+1
Alexandru Razvan Caciulescu
+3
·
Published
2018-07-05
·
Updated
2026-02-06
·
CVE-2018-13304
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
FFmpeg version 4.0.1
Description
The issue is related to improper maintenance of consistency between the context profile field and studio profile in libavcodec, which may trigger an assertion failure when converting a crafted AVI file to MPEG4. This can lead to a denial of service. The affected components include error resilience.c, h263dec.c, and mpeg4videodec.c. A remote attacker can exploit this issue using a specially crafted AVI file.
Recommendations
For FFmpeg version 4.0.1, consider disabling the affected components, such as error resilience.c, h263dec.c, and mpeg4videodec.c, as a temporary workaround to minimize the risk of exploitation.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
DoS
Assertion Failure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Ffmpeg