Описание
FFmpeg through 4.3 has a heap-based buffer overflow in avio_get_str in libavformat/aviobuf.c because dnn_backend_native.c calls ff_dnn_load_model_native and a certain index check is omitted.
Ссылки
- Not ApplicableVendor Advisory
- Third Party Advisory
- PatchVendor Advisory
- Not ApplicableVendor Advisory
- Third Party Advisory
- PatchVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 4.3 (включая) до 4.3.1 (исключая)
cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*
EPSS
Процентиль: 70%
0.00637
Низкий
8.8 High
CVSS3
6.8 Medium
CVSS2
Дефекты
CWE-787
Связанные уязвимости
CVSS3: 8.8
ubuntu
больше 5 лет назад
FFmpeg through 4.3 has a heap-based buffer overflow in avio_get_str in libavformat/aviobuf.c because dnn_backend_native.c calls ff_dnn_load_model_native and a certain index check is omitted.
CVSS3: 8.8
debian
больше 5 лет назад
FFmpeg through 4.3 has a heap-based buffer overflow in avio_get_str in ...
github
больше 3 лет назад
FFmpeg through 4.3 has a heap-based buffer overflow in avio_get_str in libavformat/aviobuf.c because dnn_backend_native.c calls ff_dnn_load_model_native and a certain index check is omitted.
EPSS
Процентиль: 70%
0.00637
Низкий
8.8 High
CVSS3
6.8 Medium
CVSS2
Дефекты
CWE-787