libavcodec/scpr.c in FFmpeg 3.3 before 3.3.1 does not properly validate height and width data, which allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted file.
References
Link | Resource |
---|---|
https://github.com/FFmpeg/FFmpeg/commit/7ac5067146613997bb38442cb022d7f41321a706 | Issue Tracking Patch Third Party Advisory |
https://github.com/FFmpeg/FFmpeg/commit/2171dfae8c065878a2e130390eb78cf2947a5b69 | Issue Tracking Patch Third Party Advisory |
https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=1519 | Issue Tracking Third Party Advisory |
https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=1478 | Issue Tracking Third Party Advisory |
http://www.securityfocus.com/bid/99320 | Third Party Advisory VDB Entry |
Configurations
Information
Published : 2017-06-27 23:29
Updated : 2017-07-03 11:59
NVD link : CVE-2017-9995
Mitre link : CVE-2017-9995
JSON object : View
CWE
CWE-119
Improper Restriction of Operations within the Bounds of a Memory Buffer
Products Affected
ffmpeg
- ffmpeg