Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2015-8364

Опубликовано: 26 нояб. 2015
Источник: nvd
CVSS2: 6.8
EPSS Низкий

Описание

Integer overflow in the ff_ivi_init_planes function in libavcodec/ivi.c in FFmpeg before 2.6.5, 2.7.x before 2.7.3, and 2.8.x through 2.8.2 allows remote attackers to cause a denial of service (out-of-bounds heap-memory access) or possibly have unspecified other impact via crafted image dimensions in Indeo Video Interactive data.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:ffmpeg:ffmpeg:2.6.4:*:*:*:*:*:*:*
cpe:2.3:a:ffmpeg:ffmpeg:2.7.0:*:*:*:*:*:*:*
cpe:2.3:a:ffmpeg:ffmpeg:2.7.1:*:*:*:*:*:*:*
cpe:2.3:a:ffmpeg:ffmpeg:2.7.2:*:*:*:*:*:*:*
cpe:2.3:a:ffmpeg:ffmpeg:2.8.0:*:*:*:*:*:*:*
cpe:2.3:a:ffmpeg:ffmpeg:2.8.1:*:*:*:*:*:*:*
cpe:2.3:a:ffmpeg:ffmpeg:2.8.2:*:*:*:*:*:*:*
Конфигурация 2
cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:lts:*:*:*

EPSS

Процентиль: 68%
0.00582
Низкий

6.8 Medium

CVSS2

Дефекты

CWE-189

Связанные уязвимости

ubuntu
около 10 лет назад

Integer overflow in the ff_ivi_init_planes function in libavcodec/ivi.c in FFmpeg before 2.6.5, 2.7.x before 2.7.3, and 2.8.x through 2.8.2 allows remote attackers to cause a denial of service (out-of-bounds heap-memory access) or possibly have unspecified other impact via crafted image dimensions in Indeo Video Interactive data.

debian
около 10 лет назад

Integer overflow in the ff_ivi_init_planes function in libavcodec/ivi. ...

github
больше 3 лет назад

Integer overflow in the ff_ivi_init_planes function in libavcodec/ivi.c in FFmpeg before 2.6.5, 2.7.x before 2.7.3, and 2.8.x through 2.8.2 allows remote attackers to cause a denial of service (out-of-bounds heap-memory access) or possibly have unspecified other impact via crafted image dimensions in Indeo Video Interactive data.

suse-cvrf
около 10 лет назад

Security update for ffmpeg

EPSS

Процентиль: 68%
0.00582
Низкий

6.8 Medium

CVSS2

Дефекты

CWE-189