{"api_version":"1","generated_at":"2026-07-23T08:15:52+00:00","cve":"CVE-2017-14055","urls":{"html":"https://cve.report/CVE-2017-14055","api":"https://cve.report/api/cve/CVE-2017-14055.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2017-14055","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2017-14055"},"summary":{"title":"CVE-2017-14055","description":"In libavformat/mvdec.c in FFmpeg 3.3.3, a DoS in mv_read_header() due to lack of an EOF (End of File) check might cause huge CPU and memory consumption. When a crafted MV file, which claims a large \"nb_frames\" field in the header but does not contain sufficient backing data, is provided, the loop over the frames would consume huge CPU and memory resources, since there is no EOF check inside the loop.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2017-08-31 15:29:00","updated_at":"2019-10-03 00:03:00"},"problem_types":["CWE-834"],"metrics":[],"references":[{"url":"https://github.com/FFmpeg/FFmpeg/commit/4f05e2e2dc1a89f38cd9f0960a6561083d714f1e","name":"https://github.com/FFmpeg/FFmpeg/commit/4f05e2e2dc1a89f38cd9f0960a6561083d714f1e","refsource":"CONFIRM","tags":["Patch","Third Party Advisory"],"title":"avformat/mvdec: Fix DoS due to lack of eof check · FFmpeg/FFmpeg@4f05e2e · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/100626","name":"100626","refsource":"BID","tags":[],"title":"FFmpeg CVE-2017-14055 Denial of Service Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://lists.debian.org/debian-lts-announce/2019/01/msg00006.html","name":"[debian-lts-announce] 20190107 [SECURITY] [DLA 1630-1] libav security update","refsource":"MLIST","tags":[],"title":"[SECURITY] [DLA 1630-1] libav security update","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.debian.org/security/2017/dsa-3996","name":"DSA-3996","refsource":"DEBIAN","tags":[],"title":"Debian -- Security Information -- DSA-3996-1 ffmpeg","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2017-14055","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2017-14055","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2017","cve_id":"14055","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ffmpeg","cpe5":"ffmpeg","cpe6":"3.3.3","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"14055","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ffmpeg","cpe5":"ffmpeg","cpe6":"3.3.3","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[{"cve":"CVE-2017-14055","qid":"500897","title":"Alpine Linux Security Update for ffmpeg"},{"cve":"CVE-2017-14055","qid":"502267","title":"Alpine Linux Security Update for ffmpeg4"},{"cve":"CVE-2017-14055","qid":"504740","title":"Alpine Linux Security Update for ffmpeg"},{"cve":"CVE-2017-14055","qid":"504758","title":"Alpine Linux Security Update for ffmpeg4"}]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2017-14055","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"In libavformat/mvdec.c in FFmpeg 3.3.3, a DoS in mv_read_header() due to lack of an EOF (End of File) check might cause huge CPU and memory consumption. When a crafted MV file, which claims a large \"nb_frames\" field in the header but does not contain sufficient backing data, is provided, the loop over the frames would consume huge CPU and memory resources, since there is no EOF check inside the loop."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"100626","refsource":"BID","url":"http://www.securityfocus.com/bid/100626"},{"name":"https://github.com/FFmpeg/FFmpeg/commit/4f05e2e2dc1a89f38cd9f0960a6561083d714f1e","refsource":"CONFIRM","url":"https://github.com/FFmpeg/FFmpeg/commit/4f05e2e2dc1a89f38cd9f0960a6561083d714f1e"},{"name":"[debian-lts-announce] 20190107 [SECURITY] [DLA 1630-1] libav security update","refsource":"MLIST","url":"https://lists.debian.org/debian-lts-announce/2019/01/msg00006.html"},{"name":"DSA-3996","refsource":"DEBIAN","url":"http://www.debian.org/security/2017/dsa-3996"}]}},"nvd":{"publishedDate":"2017-08-31 15:29:00","lastModifiedDate":"2019-10-03 00:03:00","problem_types":["CWE-834"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"},"exploitabilityScore":2.8,"impactScore":3.6},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:N/A:C","accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"COMPLETE","baseScore":7.1},"severity":"HIGH","exploitabilityScore":8.6,"impactScore":6.9,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:ffmpeg:ffmpeg:3.3.3:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2017","CveId":"14055","Ordinal":"111480","Title":"CVE-2017-14055","CVE":"CVE-2017-14055","Year":"2017"},"notes":[{"CveYear":"2017","CveId":"14055","Ordinal":"1","NoteData":"In libavformat/mvdec.c in FFmpeg 3.3.3, a DoS in mv_read_header() due to lack of an EOF (End of File) check might cause huge CPU and memory consumption. When a crafted MV file, which claims a large \"nb_frames\" field in the header but does not contain sufficient backing data, is provided, the loop over the frames would consume huge CPU and memory resources, since there is no EOF check inside the loop.","Type":"Description","Title":null},{"CveYear":"2017","CveId":"14055","Ordinal":"2","NoteData":"2017-08-31","Type":"Other","Title":"Published"},{"CveYear":"2017","CveId":"14055","Ordinal":"3","NoteData":"2019-01-08","Type":"Other","Title":"Modified"}]}}}