Skip to main content

FFmpeg Remote Code Execution Vulnerability

Last Update Date: 3 Mar 2014 12:23 Release Date: 3 Mar 2014 3188 Views

RISK: Medium Risk

TYPE: Clients - Audio & Video

TYPE: Audio & Video

A vulnerability was identified in FFmpeg. A remote user can cause arbitrary code to be executed on the target user's system.

 

A remote user can create specially crafted content that, when loaded by the target user, will trigger a buffer overflow in the mpegts_write_pmt() function and execute arbitrary code on the target system. The code will run with the privileges of the target user.

 

The vulnerability resides in 'libavformat/mpegtsenc.c'.


Impact

  • Remote Code Execution

System / Technologies affected

  • FFmpeg

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.


Vulnerability Identifier


Source


Related Link