Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2015-8218

Опубликовано: 17 нояб. 2015
Источник: debian
EPSS Низкий

Описание

The decode_uncompressed function in libavcodec/faxcompr.c in FFmpeg before 2.8.2 does not validate uncompressed runs, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted CCITT FAX data.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
ffmpegfixed7:2.8.2-1package
ffmpegnot-affectedsqueezepackage
libavnot-affectedpackage

Примечания

  • https://git.videolan.org/?p=ffmpeg.git;a=commit;h=d4a731b84a08f0f3839eaaaf82e97d8d9c67da46

  • Vulnerability affects G3{1, 2}D code extensions feature, which is not present

  • in libav 0.8 and 9. branches: https://lists.debian.org/debian-lts/2017/12/msg00011.html

  • 11.x features G3 support, but the vulnerable code was introduced later

EPSS

Процентиль: 62%
0.0043
Низкий

Связанные уязвимости

ubuntu
около 10 лет назад

The decode_uncompressed function in libavcodec/faxcompr.c in FFmpeg before 2.8.2 does not validate uncompressed runs, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted CCITT FAX data.

nvd
около 10 лет назад

The decode_uncompressed function in libavcodec/faxcompr.c in FFmpeg before 2.8.2 does not validate uncompressed runs, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted CCITT FAX data.

github
больше 3 лет назад

The decode_uncompressed function in libavcodec/faxcompr.c in FFmpeg before 2.8.2 does not validate uncompressed runs, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted CCITT FAX data.

fstec
около 10 лет назад

Уязвимость мультимедийной библиотеки FFmpeg, позволяющая нарушителю вызвать отказ в обслуживании

suse-cvrf
около 10 лет назад

Security update for ffmpeg

EPSS

Процентиль: 62%
0.0043
Низкий