CVE-2018-14395
Summary
| CVE | CVE-2018-14395 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-07-19 05:29:00 UTC |
| Updated | 2021-02-05 21:57:00 UTC |
| Description | libavformat/movenc.c in FFmpeg 3.2 and 4.0.2 allows attackers to cause a denial of service (application crash caused by a divide-by-zero error) with a user crafted audio file when converting to the MOV audio format. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| avformat/movenc: Write version 2 of audio atom if channels is not known · FFmpeg/FFmpeg@fa19fbc · GitHub |
MISC |
github.com |
Patch, Third Party Advisory |
| avformat/movenc: Write version 2 of audio atom if channels is not known · FFmpeg/FFmpeg@2c0e98a · GitHub |
MISC |
github.com |
Patch, Third Party Advisory |
| Debian -- Security Information -- DSA-4258-1 ffmpeg |
DEBIAN |
www.debian.org |
Third Party Advisory |
| FFmpeg Divide-by-Zero Error in Converting Audio Files Lets Remote Users Cause the Target Application to Crash - SecurityTracker |
SECTRACK |
www.securitytracker.com |
Third Party Advisory, VDB Entry |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 500899 Alpine Linux Security Update for ffmpeg
- 502269 Alpine Linux Security Update for ffmpeg4
- 504742 Alpine Linux Security Update for ffmpeg
- 504760 Alpine Linux Security Update for ffmpeg4