PT-2019-5777 · FFmpeg+4 · Ffmpeg+4

Published

2019-07-07

·

Updated

2023-05-05

·

CVE-2019-13390

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions FFmpeg version 4.1.3
Description The issue is related to a division by zero error in the adx write trailer function of the libavformat library in the FFmpeg multimedia environment. This error can be exploited by a remote attacker to cause a denial of service.
Recommendations For FFmpeg version 4.1.3, consider applying a patch or fix to resolve the division by zero error in the adx write trailer function as a temporary workaround, restrict access to the libavformat library to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Divide By Zero

Weakness Enumeration

Related Identifiers

ALT-PU-2019-2328
ALT-PU-2019-3126
BDU:2021-02001
CVE-2019-13390
DLA-2291-1
DSA-4722-1
OPENSUSE-SU-2023_0206-1
SUSE-SU-2023:0206-1
SUSE-SU-2023:2115-1
SUSE-SU-2023_0206-1
SUSE-SU-2023_2115-1
USN-4431-1

Affected Products

Alt Linux
Ffmpeg
Linuxmint
Suse
Ubuntu