Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2019-9721

Опубликовано: 12 мар. 2019
Источник: debian
EPSS Низкий

Описание

A denial of service in the subtitle decoder in FFmpeg 3.2 and 4.1 allows attackers to hog the CPU via a crafted video file in Matroska format, because handle_open_brace in libavcodec/htmlsubtitles.c has a complex format argument to sscanf.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
ffmpegfixed7:4.1.3-1package
ffmpegnot-affectedstretchpackage
libavremovedpackage
libavnot-affectedjessiepackage

Примечания

  • https://git.ffmpeg.org/gitweb/ffmpeg.git/commit/894995c41e0795c7a44f81adc4838dedc3932e65

EPSS

Процентиль: 71%
0.01435
Низкий

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 7 лет назад

A denial of service in the subtitle decoder in FFmpeg 3.2 and 4.1 allows attackers to hog the CPU via a crafted video file in Matroska format, because handle_open_brace in libavcodec/htmlsubtitles.c has a complex format argument to sscanf.

CVSS3: 4.3
redhat
больше 7 лет назад

A denial of service in the subtitle decoder in FFmpeg 3.2 and 4.1 allows attackers to hog the CPU via a crafted video file in Matroska format, because handle_open_brace in libavcodec/htmlsubtitles.c has a complex format argument to sscanf.

CVSS3: 6.5
nvd
больше 7 лет назад

A denial of service in the subtitle decoder in FFmpeg 3.2 and 4.1 allows attackers to hog the CPU via a crafted video file in Matroska format, because handle_open_brace in libavcodec/htmlsubtitles.c has a complex format argument to sscanf.

CVSS3: 6.5
github
больше 4 лет назад

A denial of service in the subtitle decoder in FFmpeg 3.2 and 4.1 allows attackers to hog the CPU via a crafted video file in Matroska format, because handle_open_brace in libavcodec/htmlsubtitles.c has a complex format argument to sscanf.

CVSS3: 6.5
fstec
больше 7 лет назад

Уязвимость функции handle_open_brace мультимедийной библиотеки FFmpeg, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 71%
0.01435
Низкий