Skip to main content

FFmpeg Multiple Vulnerabilities

Last Update Date: 21 Aug 2013 18:49 Release Date: 21 Aug 2013 2935 Views

RISK: Medium Risk

TYPE: Clients - Audio & Video

TYPE: Audio & Video

Multiple vulnerabilities have been identified in FFmpeg, which can be exploited by malicious people to cause a DoS (Denial of Service).

  1. A NULL pointer dereference error within the "decode_frame()" function (libavcodec/dxa.c) can be exploited to cause a crash.
  2. An out-of-bounds read error within the "h261_decode_mb()" function (libavcodec/h261dec.c) can be exploited to cause a crash.

Impact

  • Denial of Service

System / Technologies affected

  • FFmpeg 1.x
  • FFmpeg 2.x

 


Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.

  • Fixed in the git repository.

Vulnerability Identifier

  • No CVE information is available

Source


Related Link