Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2016-10191

Опубликовано: 09 фев. 2017
Источник: debian

Описание

Heap-based buffer overflow in libavformat/rtmppkt.c in FFmpeg before 2.8.10, 3.0.x before 3.0.5, 3.1.x before 3.1.6, and 3.2.x before 3.2.2 allows remote attackers to execute arbitrary code by leveraging failure to check for RTMP packet size mismatches.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
ffmpegfixed7:3.2.2-1package
libavremovedpackage

Примечания

  • Patch: https://github.com/FFmpeg/FFmpeg/commit/7d57ca4d9a75562fa32e40766211de150f8b3ee7

  • https://www.openwall.com/lists/oss-security/2017/01/31/12

Связанные уязвимости

CVSS3: 9.8
ubuntu
почти 9 лет назад

Heap-based buffer overflow in libavformat/rtmppkt.c in FFmpeg before 2.8.10, 3.0.x before 3.0.5, 3.1.x before 3.1.6, and 3.2.x before 3.2.2 allows remote attackers to execute arbitrary code by leveraging failure to check for RTMP packet size mismatches.

CVSS3: 9.8
nvd
почти 9 лет назад

Heap-based buffer overflow in libavformat/rtmppkt.c in FFmpeg before 2.8.10, 3.0.x before 3.0.5, 3.1.x before 3.1.6, and 3.2.x before 3.2.2 allows remote attackers to execute arbitrary code by leveraging failure to check for RTMP packet size mismatches.

CVSS3: 9.8
github
больше 3 лет назад

Heap-based buffer overflow in libavformat/rtmppkt.c in FFmpeg before 2.8.10, 3.0.x before 3.0.5, 3.1.x before 3.1.6, and 3.2.x before 3.2.2 allows remote attackers to execute arbitrary code by leveraging failure to check for RTMP packet size mismatches.

fstec
почти 9 лет назад

Уязвимость компонента libavformat/rtmppkt.c мультимедийной библиотеки FFmpeg, позволяющая нарушителю выполнить произвольный код

suse-cvrf
больше 8 лет назад

Security update for ffmpeg2