Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2016-9561

Опубликовано: 23 дек. 2016
Источник: debian
EPSS Низкий

Описание

The che_configure function in libavcodec/aacdec_template.c in FFmpeg before 3.2.1 allows remote attackers to cause a denial of service (allocation of huge memory, and being killed by the OS) via a crafted MOV file.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
ffmpegfixed7:3.2.4-1package

Примечания

  • https://www.openwall.com/lists/oss-security/2016/12/08/1

  • non-issue, legitimate media file. If a server application uses libav* on untrusted media

  • files, it needs to set resource limits

EPSS

Процентиль: 47%
0.00241
Низкий

Связанные уязвимости

CVSS3: 5.5
ubuntu
около 9 лет назад

The che_configure function in libavcodec/aacdec_template.c in FFmpeg before 3.2.1 allows remote attackers to cause a denial of service (allocation of huge memory, and being killed by the OS) via a crafted MOV file.

CVSS3: 5.5
nvd
около 9 лет назад

The che_configure function in libavcodec/aacdec_template.c in FFmpeg before 3.2.1 allows remote attackers to cause a denial of service (allocation of huge memory, and being killed by the OS) via a crafted MOV file.

CVSS3: 5.5
github
больше 3 лет назад

The che_configure function in libavcodec/aacdec_template.c in FFmpeg before 3.2.1 allows remote attackers to cause a denial of service (allocation of huge memory, and being killed by the OS) via a crafted MOV file.

suse-cvrf
больше 8 лет назад

Security update for ffmpeg2

suse-cvrf
больше 8 лет назад

Security update for ffmpeg, ffmpeg2

EPSS

Процентиль: 47%
0.00241
Низкий