Skip to main content

FFmpeg Multiple Vulnerabilities

Last Update Date: 17 Jul 2013 12:57 Release Date: 17 Jul 2013 3336 Views

RISK: Medium Risk

TYPE: Clients - Audio & Video

TYPE: Audio & Video

Multiple vulnerabilities have been identified in FFmpeg, where some have an unknown impact and others can be exploited by malicious people to cause a DoS (Denial of Service).

  1. A NULL pointer dereference error within the "decode_mb_info()" function (libavcodec/indeo4.c) can be exploited to cause a crash.
  2. An out-of-bounds read error within the "decode_band_hdr()" function (libavcodec/indeo4.c) can be exploited to cause a crash.
  3. Another out-of-bounds read error within the "decode_band_hdr()" function (libavcodec/indeo4.c) can be exploited to cause a crash.
  4. Some errors exist when applying certain transform.

Impact

  • Denial of Service

System / Technologies affected

  • FFmpeg 2.x

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.

  • Fixed in the GIT repository.

Vulnerability Identifier

  • No CVE information is available

Source


Related Link