Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-96rf-5r43-949p

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

libavcodec/hevcdec.c in FFmpeg 4.1.2 mishandles detection of duplicate first slices, which allows remote attackers to cause a denial of service (NULL pointer dereference and out-of-array access) or possibly have unspecified other impact via crafted HEVC data.

libavcodec/hevcdec.c in FFmpeg 4.1.2 mishandles detection of duplicate first slices, which allows remote attackers to cause a denial of service (NULL pointer dereference and out-of-array access) or possibly have unspecified other impact via crafted HEVC data.

EPSS

Процентиль: 83%
0.02027
Низкий

8.8 High

CVSS3

Дефекты

CWE-476

Связанные уязвимости

CVSS3: 8.8
ubuntu
почти 7 лет назад

libavcodec/hevcdec.c in FFmpeg 3.4 and 4.1.2 mishandles detection of duplicate first slices, which allows remote attackers to cause a denial of service (NULL pointer dereference and out-of-array access) or possibly have unspecified other impact via crafted HEVC data.

CVSS3: 8.8
nvd
почти 7 лет назад

libavcodec/hevcdec.c in FFmpeg 3.4 and 4.1.2 mishandles detection of duplicate first slices, which allows remote attackers to cause a denial of service (NULL pointer dereference and out-of-array access) or possibly have unspecified other impact via crafted HEVC data.

CVSS3: 8.8
debian
почти 7 лет назад

libavcodec/hevcdec.c in FFmpeg 3.4 and 4.1.2 mishandles detection of d ...

CVSS3: 8.8
fstec
почти 7 лет назад

Уязвимость мультимедийной библиотеки FFmpeg, связанная с разыменованием нулевого указателя, позволяющая нарушителю вызвать отказ в обслуживании

suse-cvrf
около 6 лет назад

Security update for ffmpeg-4

EPSS

Процентиль: 83%
0.02027
Низкий

8.8 High

CVSS3

Дефекты

CWE-476