aa_read_header in libavformat/aadec.c in FFmpeg before 3.2.14 and 4.x before 4.1.4 does not check for sscanf failure and consequently allows use of uninitialized variables.
References
Configurations
Information
Published : 2019-06-04 07:29
Updated : 2020-08-24 10:37
NVD link : CVE-2019-12730
Mitre link : CVE-2019-12730
JSON object : View
CWE
CWE-908
Use of Uninitialized Resource
Products Affected
ffmpeg
- ffmpeg