Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2015-8663

Опубликовано: 24 дек. 2015
Источник: debian
EPSS Низкий

Описание

The ff_get_buffer function in libavcodec/utils.c in FFmpeg before 2.8.4 preserves width and height values after a failure, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via a crafted .mov file.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
ffmpegfixed7:2.8.4-1package
ffmpegend-of-lifesqueezepackage
libavremovedpackage

Примечания

  • https://git.videolan.org/?p=ffmpeg.git;a=commit;h=abee0a1c60612e8638640a8a3738fffb65e16dbf

  • For libav in jessie the patch needs to applied in libavcodec/decode.c in line 1884.

EPSS

Процентиль: 78%
0.01913
Низкий

Связанные уязвимости

CVSS3: 8.3
ubuntu
больше 10 лет назад

The ff_get_buffer function in libavcodec/utils.c in FFmpeg before 2.8.4 preserves width and height values after a failure, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via a crafted .mov file.

CVSS3: 8.3
nvd
больше 10 лет назад

The ff_get_buffer function in libavcodec/utils.c in FFmpeg before 2.8.4 preserves width and height values after a failure, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via a crafted .mov file.

CVSS3: 8.3
github
больше 4 лет назад

The ff_get_buffer function in libavcodec/utils.c in FFmpeg before 2.8.4 preserves width and height values after a failure, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via a crafted .mov file.

fstec
больше 10 лет назад

Уязвимость мультимедийной библиотеки FFmpeg, позволяющая нарушителю вызвать отказ в обслуживании или оказать другое воздействие

suse-cvrf
больше 10 лет назад

Security update for ffmpeg

EPSS

Процентиль: 78%
0.01913
Низкий