FFmpeg 'libavcodec/rawdec.c' Out of Bounds Denial of Service Vulnerability
BID:71618
Info
FFmpeg 'libavcodec/rawdec.c' Out of Bounds Denial of Service Vulnerability
| Bugtraq ID: | 71618 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2014-9318 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 09 2014 12:00AM |
| Updated: | Jul 05 2016 09:43PM |
| Credit: | Mateusz "j00ru" Jurczyk, and Gynvael Coldwind |
| Vulnerable: |
Gentoo Linux |
| Not Vulnerable: | |
Discussion
FFmpeg 'libavcodec/rawdec.c' Out of Bounds Denial of Service Vulnerability
FFmpeg is prone to a denial-of-service vulnerability.
An attacker can exploit this issue to crash the affected application, denying service to legitimate users. Due to the nature of this issue, code-execution may be possible; however this has not been confirmed.
The following versions are vulnerable:
Versions prior to FFmpeg 2.1.6
FFmpeg 2.2.x through 2.3.x
FFmpeg 2.4.x versions prior to 2.4.4
FFmpeg is prone to a denial-of-service vulnerability.
An attacker can exploit this issue to crash the affected application, denying service to legitimate users. Due to the nature of this issue, code-execution may be possible; however this has not been confirmed.
The following versions are vulnerable:
Versions prior to FFmpeg 2.1.6
FFmpeg 2.2.x through 2.3.x
FFmpeg 2.4.x versions prior to 2.4.4