CVE-2015-3395
Summary
| CVE | CVE-2015-3395 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2015-06-16 16:59:04 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | The msrle_decode_pal4 function in msrledec.c in Libav before 10.7 and 11.x before 11.4 and FFmpeg before 2.0.7, 2.2.x before 2.2.15, 2.4.x before 2.4.8, 2.5.x before 2.5.6, and 2.6.x before 2.6.2 allows remote attackers to have unspecified impact via a crafted image, related to a pixel pointer, which triggers an out-of-bounds array access. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:M/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Canonical | Ubuntu Linux | 12.04 | All | All | All |
| Application | Ffmpeg | Ffmpeg | 2.0.6 | All | All | All |
| Application | Ffmpeg | Ffmpeg | 2.2.0 | All | All | All |
| Application | Ffmpeg | Ffmpeg | 2.2.1 | All | All | All |
| Application | Ffmpeg | Ffmpeg | 2.2.10 | All | All | All |
| Application | Ffmpeg | Ffmpeg | 2.2.11 | All | All | All |
| Application | Ffmpeg | Ffmpeg | 2.2.12 | All | All | All |
| Application | Ffmpeg | Ffmpeg | 2.2.13 | All | All | All |
| Application | Ffmpeg | Ffmpeg | 2.2.14 | All | All | All |
| Application | Ffmpeg | Ffmpeg | 2.2.2 | All | All | All |
| Application | Ffmpeg | Ffmpeg | 2.2.3 | All | All | All |
| Application | Ffmpeg | Ffmpeg | 2.2.4 | All | All | All |
| Application | Ffmpeg | Ffmpeg | 2.2.5 | All | All | All |
| Application | Ffmpeg | Ffmpeg | 2.2.6 | All | All | All |
| Application | Ffmpeg | Ffmpeg | 2.2.7 | All | All | All |
| Application | Ffmpeg | Ffmpeg | 2.2.8 | All | All | All |
| Application | Ffmpeg | Ffmpeg | 2.2.9 | All | All | All |
| Application | Ffmpeg | Ffmpeg | 2.4.0 | All | All | All |
| Application | Ffmpeg | Ffmpeg | 2.4.1 | All | All | All |
| Application | Ffmpeg | Ffmpeg | 2.4.2 | All | All | All |
| Application | Ffmpeg | Ffmpeg | 2.4.3 | All | All | All |
| Application | Ffmpeg | Ffmpeg | 2.4.4 | All | All | All |
| Application | Ffmpeg | Ffmpeg | 2.4.5 | All | All | All |
| Application | Ffmpeg | Ffmpeg | 2.4.6 | All | All | All |
| Application | Ffmpeg | Ffmpeg | 2.4.7 | All | All | All |
| Application | Ffmpeg | Ffmpeg | 2.5.0 | All | All | All |
| Application | Ffmpeg | Ffmpeg | 2.5.1 | All | All | All |
| Application | Ffmpeg | Ffmpeg | 2.5.2 | All | All | All |
| Application | Ffmpeg | Ffmpeg | 2.5.3 | All | All | All |
| Application | Ffmpeg | Ffmpeg | 2.5.4 | All | All | All |
| Application | Ffmpeg | Ffmpeg | 2.5.5 | All | All | All |
| Application | Ffmpeg | Ffmpeg | 2.6.0 | All | All | All |
| Application | Ffmpeg | Ffmpeg | 2.6.1 | All | All | All |
| Application | Libav | Libav | 11.0 | All | All | All |
| Application | Libav | Libav | 11.1 | All | All | All |
| Application | Libav | Libav | 11.2 | All | All | All |
| Application | Libav | Libav | 11.3 | All | All | All |
| Application | Libav | Libav | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| FFmpeg Security | af854a3a-2127-422b-91ae-364da2661108 | www.ffmpeg.org | Vendor Advisory |
| FFmpeg: Multiple vulnerabilities (GLSA 201603-06) — Gentoo Security | af854a3a-2127-422b-91ae-364da2661108 | security.gentoo.org | |
| git.libav.org Git - libav.git/blob - Changelog | af854a3a-2127-422b-91ae-364da2661108 | git.libav.org | |
| git.videolan.org Git - ffmpeg.git/commitdiff | af854a3a-2127-422b-91ae-364da2661108 | git.videolan.org | |
| libav: Multiple vulnerabilities (GLSA 201705-08) — Gentoo Security | af854a3a-2127-422b-91ae-364da2661108 | security.gentoo.org | |
| FFmpeg 'msrledec.c' Out of Bounds Denial of Service Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Debian -- Security Information -- DSA-3288-1 libav | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| USN-2944-1: Libav vulnerabilities | Ubuntu | af854a3a-2127-422b-91ae-364da2661108 | www.ubuntu.com | |
| git.videolan.org Git - ffmpeg.git/commitdiff | MITRE | git.videolan.org | |
| git.libav.org Git - libav.git/blob - Changelog | MITRE | git.libav.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 710503 Gentoo Linux libav Multiple Vulnerabilities (GLSA 201705-08)