FFmpeg Remote Code Execution Vulnerability
RISK: Medium Risk
TYPE: Clients - Audio & Video
A vulnerability was identified in FFmpeg. A remote user can cause arbitrary code to be executed on the target user's system.
A remote user can create specially crafted content that, when loaded by the target user, will trigger a buffer overflow in the mpegts_write_pmt() function and execute arbitrary code on the target system. The code will run with the privileges of the target user.
The vulnerability resides in 'libavformat/mpegtsenc.c'.
Impact
- Remote Code Execution
System / Technologies affected
- FFmpeg
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- The vendor has issued a source code fix, available at:
http://git.videolan.org/?p=ffmpeg.git;a=commit;h=842b6c14bc
Vulnerability Identifier
Source
Related Link
Share with