Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-27fw-6hp8-fgww

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

The av_color_primaries_name function in libavutil/pixdesc.c in FFmpeg 3.3.3 may return a NULL pointer depending on a value contained in a file, but callers do not anticipate this, as demonstrated by the avcodec_string function in libavcodec/utils.c, leading to a NULL pointer dereference. (It is also conceivable that there is security relevance for a NULL pointer dereference in av_color_primaries_name calls within the ffprobe command-line program.)

The av_color_primaries_name function in libavutil/pixdesc.c in FFmpeg 3.3.3 may return a NULL pointer depending on a value contained in a file, but callers do not anticipate this, as demonstrated by the avcodec_string function in libavcodec/utils.c, leading to a NULL pointer dereference. (It is also conceivable that there is security relevance for a NULL pointer dereference in av_color_primaries_name calls within the ffprobe command-line program.)

EPSS

Процентиль: 59%
0.0038
Низкий

8.8 High

CVSS3

Дефекты

CWE-476

Связанные уязвимости

CVSS3: 8.8
ubuntu
почти 8 лет назад

The av_color_primaries_name function in libavutil/pixdesc.c in FFmpeg 3.3.3 may return a NULL pointer depending on a value contained in a file, but callers do not anticipate this, as demonstrated by the avcodec_string function in libavcodec/utils.c, leading to a NULL pointer dereference. (It is also conceivable that there is security relevance for a NULL pointer dereference in av_color_primaries_name calls within the ffprobe command-line program.)

CVSS3: 8.8
nvd
почти 8 лет назад

The av_color_primaries_name function in libavutil/pixdesc.c in FFmpeg 3.3.3 may return a NULL pointer depending on a value contained in a file, but callers do not anticipate this, as demonstrated by the avcodec_string function in libavcodec/utils.c, leading to a NULL pointer dereference. (It is also conceivable that there is security relevance for a NULL pointer dereference in av_color_primaries_name calls within the ffprobe command-line program.)

CVSS3: 8.8
debian
почти 8 лет назад

The av_color_primaries_name function in libavutil/pixdesc.c in FFmpeg ...

suse-cvrf
почти 8 лет назад

Security update for ffmpeg, ffmpeg2

suse-cvrf
почти 8 лет назад

Security update for ffmpeg, ffmpeg2

EPSS

Процентиль: 59%
0.0038
Низкий

8.8 High

CVSS3

Дефекты

CWE-476