Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2016-10190

Опубликовано: 09 фев. 2017
Источник: debian

Описание

Heap-based buffer overflow in libavformat/http.c in FFmpeg before 2.8.10, 3.0.x before 3.0.5, 3.1.x before 3.1.6, and 3.2.x before 3.2.2 allows remote web servers to execute arbitrary code via a negative chunk size in an HTTP response.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
ffmpegfixed7:3.2.2-1package
libavremovedpackage

Примечания

  • Patch: https://github.com/FFmpeg/FFmpeg/commit/2a05c8f813de6f2278827734bf8102291e7484aa

  • https://www.openwall.com/lists/oss-security/2017/01/31/12

Связанные уязвимости

CVSS3: 9.8
ubuntu
почти 9 лет назад

Heap-based buffer overflow in libavformat/http.c in FFmpeg before 2.8.10, 3.0.x before 3.0.5, 3.1.x before 3.1.6, and 3.2.x before 3.2.2 allows remote web servers to execute arbitrary code via a negative chunk size in an HTTP response.

CVSS3: 9.8
nvd
почти 9 лет назад

Heap-based buffer overflow in libavformat/http.c in FFmpeg before 2.8.10, 3.0.x before 3.0.5, 3.1.x before 3.1.6, and 3.2.x before 3.2.2 allows remote web servers to execute arbitrary code via a negative chunk size in an HTTP response.

CVSS3: 9.8
github
больше 3 лет назад

Heap-based buffer overflow in libavformat/http.c in FFmpeg before 2.8.10, 3.0.x before 3.0.5, 3.1.x before 3.1.6, and 3.2.x before 3.2.2 allows remote web servers to execute arbitrary code via a negative chunk size in an HTTP response.

fstec
почти 9 лет назад

Уязвимость компонента мультимедийной библиотеки FFmpeg, позволяющая нарушителю выполнить произвольный код

suse-cvrf
больше 8 лет назад

Security update for ffmpeg2