Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2015-8663

Опубликовано: 24 дек. 2015
Источник: debian
EPSS Низкий

Описание

The ff_get_buffer function in libavcodec/utils.c in FFmpeg before 2.8.4 preserves width and height values after a failure, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via a crafted .mov file.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
ffmpegfixed7:2.8.4-1package
ffmpegend-of-lifesqueezepackage
libavremovedpackage

Примечания

  • https://git.videolan.org/?p=ffmpeg.git;a=commit;h=abee0a1c60612e8638640a8a3738fffb65e16dbf

  • For libav in jessie the patch needs to applied in libavcodec/decode.c in line 1884.

EPSS

Процентиль: 71%
0.00683
Низкий

Связанные уязвимости

CVSS3: 8.3
ubuntu
около 10 лет назад

The ff_get_buffer function in libavcodec/utils.c in FFmpeg before 2.8.4 preserves width and height values after a failure, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via a crafted .mov file.

CVSS3: 8.3
nvd
около 10 лет назад

The ff_get_buffer function in libavcodec/utils.c in FFmpeg before 2.8.4 preserves width and height values after a failure, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via a crafted .mov file.

CVSS3: 8.3
github
больше 3 лет назад

The ff_get_buffer function in libavcodec/utils.c in FFmpeg before 2.8.4 preserves width and height values after a failure, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via a crafted .mov file.

fstec
около 10 лет назад

Уязвимость мультимедийной библиотеки FFmpeg, позволяющая нарушителю вызвать отказ в обслуживании или оказать другое воздействие

suse-cvrf
около 10 лет назад

Security update for ffmpeg

EPSS

Процентиль: 71%
0.00683
Низкий